VDB

GCVE-110-OSM-2026-11241

GCVE-110-OSM-2026-11241
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 27, 2026
This legitimate package has been compromised by North Korean theat actors for version 2.13.0. Versions before 2.13.x are safe. The compromised version of the scripts/postinstall.cjs has a PolinRider malicious JavaScript payload appended to the end of it. NullReceiver npm supply-chain package containing a benign-looking postinstall configuration routine followed by an obfuscated blockchain-resolved payload loader. Analysis confirmed multiple downloaded JavaScript stages and dynamic execution behavior. The postinstall script first creates a TestRelic configuration file, then enters an appended obfuscated loader during fresh non-CI dependency installations. The loader queries public Ethereum JSON-RPC providers and searches transactions from a campaign controller address. The recipient address encodes two HTTP C2 host-and-port combinations. One branch retrieves a boot response for direct eval and detached Node execution, including a WSL2 node.exe branch; this endpoint repeatedly timed out and remains unavailable. The second branch was recovered and statically decoded. It retrieves an XOR-encrypted body and evaluates the decoded JavaScript. Two independently downloaded snapshots of that body were byte-for-byte identical. The decoded body contains dormant cross-platform host collection, filesystem discovery, upload, command execution, Python deployment, retry, extraction, and cleanup logic. However, the exact body served during analysis is non-functional: its startup string-array decoder never completes a checksum evaluation, its cache stops changing after rotation 840, and it remains trapped after repeated complete array cycles. Consequently, the embedded stealer and downstream downloader logic is unreachable in the delivered body. No durable persistence was confirmed. The Ethereum dead drop was checked again later and continued to advertise the same C2 coordinates.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@testrelic/playwright-analytics2.13.0 (affected)

Browse GCVE Records

1,469 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›