VDB
GCVE-110-OSM-2026-10996
GCVE-110-OSM-2026-10996
Advisory PublishedCVSS 5.4/10
The package was found to contain malicious code or consuming dependency that contains malicious code
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Judge assessment: This looks like a likely attacker-controlled or test package rather than a clean library: the publisher has 21 similarly named packages, a very new account, and the package itself is only a few days old with no repository. The only code evidence shown is a static HTML page that impersonates Google Classroom, and the persistence hit on `.profile` from `index.html` is odd but not enough by itself to prove actual startup persistence or exfiltration. Because the package is labeled a security holding package and `securityHoldingRecovered` is true, the maliciousness claim is not fully substantiated from the visible payload; however, the burner-account metadata and OSV MAL advisory justify escalation for manual review. Attacker model: a low-effort supply-chain operator using throwaway npm accounts and branded lure pages to distribute a potentially malicious package or hold a namespace.
ENTRY
index.html (main: index.html)
PERSISTENCE
- Startup Persistence in index.html: ".profile"
ADDITIONAL FINDINGS
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
PAYLOAD FILES
index.html
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | schoolwork | all (affected) | — |
Aliases
Browse GCVE Records
3,587 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.