VDB

GCVE-110-OSM-2026-11348

GCVE-110-OSM-2026-11348
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 29, 2026
This package is part of a large coordinated npm registry software supply chain threat campaign involving more than 700 education-themed and randomly suffixed package names. Analyzed packages impersonate products such as secure testing browsers, ClassLink, and Desmos while distributing substantially identical browser-based unblocked-games content. The packages contain no npm lifecycle hooks or confirmed host-level malware. Their risk begins when the bundled HTML is opened: it loads mutable third-party catalogs and executes remotely controlled web content inside frames, Blob URLs, and deceptively disguised browser windows. The package contains an HTML portal for unblocked games, web proxies, and school-filter bypass services. Some variants export the complete HTML page as a JavaScript string, while larger variants package the same game loader inside a broader Dominum portal. When opened in a browser, the portal retrieves remote JSON catalogs that supply game names, images, and destination URLs. Selecting a game can cause catalog-controlled HTML to be fetched and rendered through a Blob URL, injected into an about:blank window, or loaded directly into an iframe. Some windows are styled with Google Drive or Google Classroom titles and icons to conceal their purpose. Users can also save retrieved remote HTML as local game files. Larger variants add a browser proxy interface, an Eaglercraft/Minecraft launcher, panic-key redirects, social and streaming links, and a local settings export containing same-origin preferences and cookies. The included proxy page references a service worker, Scramjet, BareMux, libcurl, and a WebSocket relay, but the required proxy components are absent from the analyzed npm archives and may be supplied only by an external hosting environment. No npm install hooks, Node.js subprocess execution, native payloads, filesystem persistence, credential collection, automatic cookie exfiltration, cryptocurrency activity, or confirmed host compromise were identified. All observed network activity is browser-side. The primary risk is execution of mutable remote HTML that can later deliver advertising, tracking, phishing, redirects, or additional browser-based content not present in the npm package.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown3layerdipstacke2eppxall (affected)

References

advisory
vendor

Browse GCVE Records

405 records in the GCVE database · Updated August 30, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›