VDB

GCVE-110-OSM-2026-11132

GCVE-110-OSM-2026-11132
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 13, 2026
The publisher 'henryp52uflores' has a publisherMaliciousRatio of 1.0 across all 24 packages — every single prior package from this account has been flagged as malicious in OSM, which is an extremely strong adversarial signal. The package itself contains a Cloudflare Turnstile CAPTCHA page as its npm 'main' entrypoint (index.html), which is a known social-engineering technique used to harvest Turnstile tokens or fingerprint victims. The onTurnstileComplete callback in index.html contains heavily obfuscated JavaScript using string-array rotation and arithmetic obfuscation (_0x4724de, _0x224e shuffling), a classic attacker pattern to hide the actual payload executed after CAPTCHA completion. The burner-account pattern — 8-day-old account, 24 random-named packages all confirmed malicious — confirms this is a coordinated malicious publishing campaign, not a legitimate developer. The obfuscated callback executing on CAPTCHA completion in an npm package (not a website) makes no legitimate sense and is consistent with credential harvesting or environment exfiltration executed post-install or at import time. ENTRY index.html (main: index.html) OBFUSCATION - String Array Obfuscation in index.html: "['nde5mZa2mhv3ALjirG','sMnpA1a','kcGOlISPkYKRkq','mtyYnffMsKDczq','CM4GDgHPCYiPk..." ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages - Publisher Shows Burner-Account Pattern

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownbgfuqg1vac5nall (affected)

References

vendor

Browse GCVE Records

3,019 records in the GCVE database · Updated September 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›