VDB

GCVE-110-OSM-2026-11031

GCVE-110-OSM-2026-11031
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 25, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code. ENTRY index.html (main: index.html) DESTINATION - 75 exfil (custom-c2) - 2 loader (loader) (values recorded in verified_iocs) EXFIL - Corporate Environment Targeting in index.html: "tModuleId found on rootModuleConfigs.\");for(let s of Ue(o)){let a=o[s];n.isComp..." - Data Encoding for Exfiltration in index.html: "encodeURIComponent(t);if(e.length){let r=e.split(\"#\"),o=/\\?/.test(e)?`${r[0]}..." - Dynamic C2 Endpoint Construction in index.html: "function VU(r){let e=[];for(let t of r)e.push(TA(t));return e}function BU(r){let..." - Suspicious Domain in index.html: "https://marylandpublicschools.org" OBFUSCATION - String Array Obfuscation in index.html: "["abs","ans","arccosh","arccot","arccoth","arccsc","arccsch","arcsec","arcsech",..." - Unicode Escape Obfuscation in index.html: "\u201A\u2044\u20AC\u2039\u203A\uFB01\uFB02\u2021" ADDITIONAL FINDINGS - Dynamic Code Execution in index.html: "eval(__dcg_shared_module_source__)" - XOR-Encoded String Arrays in index.html: "var Hne=[1,2,6,5,7,8,20,21,18,17,19,24,23]" - Clipboard Access in index.html: "navigator.clipboard.writeText" - Brand New Package - Very New NPM Publisher Account - Publisher Shows Burner-Account Pattern PAYLOAD FILES index.html

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndesmoshomeworkall (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›