VDB

GCVE-110-OSM-2026-11368

GCVE-110-OSM-2026-11368
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 29, 2026
This package is part of a large coordinated npm registry software supply chain threat campaign involving more than 700 education-themed and randomly suffixed package names. Analyzed packages impersonate products such as secure testing browsers, ClassLink, and Desmos while distributing substantially similar obfuscated JavaScript. Some packages also claim Ollama integrations but only load the public llama3.2 model from the official library. The malicious payload executes at page load when the package is imported into a browser-based application. It conditionally injects a full-screen iframe that loads remote HTML from education themed HTTPS endpoints hosted on Vercel and tries to keep the content on top by reinserting the iframe every 100 ms. The remote content is not bundled in the package and is fully controlled by the hosting environment.\n\nNo npm install hooks, Node.js subprocess execution, native payloads, filesystem persistence, credential collection, automatic cookie exfiltration, cryptocurrency activity, or confirmed host compromise were identified. All observed network activity is browser-side. The primary risk is execution of mutable remote HTML that can later deliver advertising, tracking, phishing, redirects, or additional browser-based content not present in the npm package.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown3layerdipstackgcno4all (affected)

References

advisory
vendor

Browse GCVE Records

405 records in the GCVE database · Updated August 30, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›