VDB
GCVE-110-OSM-2026-11132
GCVE-110-OSM-2026-11132
Advisory PublishedCVSS 9.6/10
The publisher 'henryp52uflores' has a publisherMaliciousRatio of 1.0 across all 24 packages — every single prior package from this account has been flagged as malicious in OSM, which is an extremely strong adversarial signal. The package itself contains a Cloudflare Turnstile CAPTCHA page as its npm 'main' entrypoint (index.html), which is a known social-engineering technique used to harvest Turnstile tokens or fingerprint victims. The onTurnstileComplete callback in index.html contains heavily obfuscated JavaScript using string-array rotation and arithmetic obfuscation (_0x4724de, _0x224e shuffling), a classic attacker pattern to hide the actual payload executed after CAPTCHA completion. The burner-account pattern — 8-day-old account, 24 random-named packages all confirmed malicious — confirms this is a coordinated malicious publishing campaign, not a legitimate developer. The obfuscated callback executing on CAPTCHA completion in an npm package (not a website) makes no legitimate sense and is consistent with credential harvesting or environment exfiltration executed post-install or at import time.
ENTRY
index.html (main: index.html)
OBFUSCATION
- String Array Obfuscation in index.html: "['nde5mZa2mhv3ALjirG','sMnpA1a','kcGOlISPkYKRkq','mtyYnffMsKDczq','CM4GDgHPCYiPk..."
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
- Publisher Shows Burner-Account Pattern
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | bgfuqg1vac5n | all (affected) | — |
Browse GCVE Records
3,019 records in the GCVE database · Updated September 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.