VDB
GCVE-110-OSM-2026-11119
GCVE-110-OSM-2026-11119
Advisory PublishedCVSS 5.4/10
This looks like a likely burner/throwaway package used as a security-holding or staging asset rather than a normal library: the publisher account is extremely new, has 24 randomly named packages, and the package itself has no repository while being published under a generic holding description. The entrypoint is an `index.html` that is essentially a Cloudflare Turnstile challenge page, which is unusual for an npm package and suggests the real payload may be hidden behind a verification gate or delivery mechanism. The `string-array-obfuscation` finding in `index.html` adds to the concern even though no exfiltration was recovered; taken together, this is consistent with a staged loader or test artifact by an unknown attacker model rather than benign package code.
ENTRY
index.html (main: index.html)
OBFUSCATION
- String Array Obfuscation in index.html: "['qxzKv3e','ugvYz1G','ANztDLm','Cwnvzhu','Bg9JyxrPB24','CM9HvKe','C2vHCMnOugfYyq..."
ADDITIONAL FINDINGS
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | nihzvdeowx5 | all (affected) | — |
Aliases
Browse GCVE Records
3,521 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.