VDB

GCVE-110-OSM-2026-11119

GCVE-110-OSM-2026-11119
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 12, 2026
This looks like a likely burner/throwaway package used as a security-holding or staging asset rather than a normal library: the publisher account is extremely new, has 24 randomly named packages, and the package itself has no repository while being published under a generic holding description. The entrypoint is an `index.html` that is essentially a Cloudflare Turnstile challenge page, which is unusual for an npm package and suggests the real payload may be hidden behind a verification gate or delivery mechanism. The `string-array-obfuscation` finding in `index.html` adds to the concern even though no exfiltration was recovered; taken together, this is consistent with a staged loader or test artifact by an unknown attacker model rather than benign package code. ENTRY index.html (main: index.html) OBFUSCATION - String Array Obfuscation in index.html: "['qxzKv3e','ugvYz1G','ANztDLm','Cwnvzhu','Bg9JyxrPB24','CM9HvKe','C2vHCMnOugfYyq..." ADDITIONAL FINDINGS - Very New NPM Publisher Account - Publisher Shows Burner-Account Pattern

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownnihzvdeowx5all (affected)

References

advisory
vendor

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›