VDB

GCVE-110-OSM-2026-11551

GCVE-110-OSM-2026-11551
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 1, 2026
The npm package randomunblockedwebsite@1.0.0 contains obfuscated browser-proxy functionality disguised among approximately 26 MB of copied Cosmos chain-registry data. Its bundled HTML and SVG entry points masquerade as an educational tutoring website while dynamically downloading and executing JavaScript from the GitHub-backed jsDelivr path cdn.jsdelivr.net/gh/TongSherbet/storage/. When either browser document is opened, it injects a remote loader.js script with an hourly cache-busting query parameter. Bundled service-worker files separately import the remote jet/jet.sw.js payload, claim browser clients, intercept requests, and pass selected traffic to a remotely supplied Scramjet proxy controller. The service worker can delete the __scramjet_controller IndexedDB database, delete all Cache Storage entries for the affected origin, unregister itself, and reload controlled browser windows. The remote scripts were not retrieved, so downstream data collection, additional payload delivery, and proxy behavior remain unresolved. No direct credential theft, native command execution, cryptocurrency transactions, or operating-system persistence was identified in the locally available files. The package’s declared npm entry point also attempts to proxy an HttpProvider from an undeclared package named supersignature. In the analyzed version, that branch is broken because it calls an undefined loadHttpProvider() function, making the dynamic import unreachable through the exported API. The complete recovered chain: 1. Disguises itself as an educational website. 2. Downloads an obfuscated proxy bootstrapper. 3. Registers a persistent service worker. 4. Loads Jet/Scramjet-style rewriting components and WASM. 5. Selects a Wisp WebSocket relay from several unrelated domains. 6. Rewrites and proxies HTTP, HTTPS, and WebSocket traffic. 7. Maintains virtual cookies in IndexedDB. 8. Forwards proxied URLs, methods, headers, bodies, referrers, cookies, client URLs, and browser metadata through the transport. 9. Loads a remote “Opium” proxy and games interface. 10. Downloads and executes mutable remote code using eval(). 11. Generates concealed popunder traffic to watchingprefecture.com. 12. Attempts to evaluate another mutable script from c.vipersfutbol.com. ENTRY index.svg (main: index.svg) OBFUSCATION - Unicode Escape Obfuscation in sw.js: "\u0075\u0073\u0065\u0072\u0041\u0067\u0065\u006E\u0074" - Obfuscation (osm-deobfuscator): unknown in sw.js - Decoded Unicode Escape Content in sw.js (x39) - Strings Extracted from Deobfuscated Code in sw.js - Obfuscation patterns: hexVariables, unicodeHeavy in sw.js ADDITIONAL FINDINGS - Brand New Package PAYLOAD FILES sw.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownrandomunblockedwebsiteall (affected)

References

advisory
vendor

Browse GCVE Records

3,425 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›