VDB
GCVE-110-OSM-2026-11368
GCVE-110-OSM-2026-11368
Advisory PublishedCVSS 8.8/10
This package is part of a large coordinated npm registry software supply chain threat campaign involving more than 700 education-themed and randomly suffixed package names. Analyzed packages impersonate products such as secure testing browsers, ClassLink, and Desmos while distributing substantially similar obfuscated JavaScript. Some packages also claim Ollama integrations but only load the public llama3.2 model from the official library.
The malicious payload executes at page load when the package is imported into a browser-based application. It conditionally injects a full-screen iframe that loads remote HTML from education themed HTTPS endpoints hosted on Vercel and tries to keep the content on top by reinserting the iframe every 100 ms. The remote content is not bundled in the package and is fully controlled by the hosting environment.\n\nNo npm install hooks, Node.js subprocess execution, native payloads, filesystem persistence, credential collection, automatic cookie exfiltration, cryptocurrency activity, or confirmed host compromise were identified. All observed network activity is browser-side. The primary risk is execution of mutable remote HTML that can later deliver advertising, tracking, phishing, redirects, or additional browser-based content not present in the npm package.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | 3layerdipstackgcno4 | all (affected) | — |
Aliases
Browse GCVE Records
405 records in the GCVE database · Updated August 30, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.