VDB

GCVE-110-OSM-2026-10996

GCVE-110-OSM-2026-10996
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 26, 2026
The package was found to contain malicious code or consuming dependency that contains malicious code Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Judge assessment: This looks like a likely attacker-controlled or test package rather than a clean library: the publisher has 21 similarly named packages, a very new account, and the package itself is only a few days old with no repository. The only code evidence shown is a static HTML page that impersonates Google Classroom, and the persistence hit on `.profile` from `index.html` is odd but not enough by itself to prove actual startup persistence or exfiltration. Because the package is labeled a security holding package and `securityHoldingRecovered` is true, the maliciousness claim is not fully substantiated from the visible payload; however, the burner-account metadata and OSV MAL advisory justify escalation for manual review. Attacker model: a low-effort supply-chain operator using throwaway npm accounts and branded lure pages to distribute a potentially malicious package or hold a namespace. ENTRY index.html (main: index.html) PERSISTENCE - Startup Persistence in index.html: ".profile" ADDITIONAL FINDINGS - Very New NPM Publisher Account - Publisher Shows Burner-Account Pattern PAYLOAD FILES index.html

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownschoolworkall (affected)

References

advisory
vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›