VDB
GCVE-110-OSM-2026-11031
GCVE-110-OSM-2026-11031
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code.
ENTRY
index.html (main: index.html)
DESTINATION
- 75 exfil (custom-c2)
- 2 loader (loader)
(values recorded in verified_iocs)
EXFIL
- Corporate Environment Targeting in index.html: "tModuleId found on rootModuleConfigs.\");for(let s of Ue(o)){let a=o[s];n.isComp..."
- Data Encoding for Exfiltration in index.html: "encodeURIComponent(t);if(e.length){let r=e.split(\"#\"),o=/\\?/.test(e)?`${r[0]}..."
- Dynamic C2 Endpoint Construction in index.html: "function VU(r){let e=[];for(let t of r)e.push(TA(t));return e}function BU(r){let..."
- Suspicious Domain in index.html: "https://marylandpublicschools.org"
OBFUSCATION
- String Array Obfuscation in index.html: "["abs","ans","arccosh","arccot","arccoth","arccsc","arccsch","arcsec","arcsech",..."
- Unicode Escape Obfuscation in index.html: "\u201A\u2044\u20AC\u2039\u203A\uFB01\uFB02\u2021"
ADDITIONAL FINDINGS
- Dynamic Code Execution in index.html: "eval(__dcg_shared_module_source__)"
- XOR-Encoded String Arrays in index.html: "var Hne=[1,2,6,5,7,8,20,21,18,17,19,24,23]"
- Clipboard Access in index.html: "navigator.clipboard.writeText"
- Brand New Package
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
PAYLOAD FILES
index.html
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | desmoshomework | all (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.