VDB

GCVE-110-OSM-2026-11603

GCVE-110-OSM-2026-11603
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 3, 2026
W3PI-Protocol/w3pi-contracts is a GitHub repository linked to the DPRK-attributed Contagious Interview campaign. The repository is tied to the w3pi.social project that operators used to lure macOS victims into installing trojanized applications delivering the OtterCookie RAT. Published June 2026 and inactive since, the repo forms part of the social-engineering front (fake Web3 project) used to build credibility for the fake interview lure. Associated C2 infrastructure: - Primary C2: 162.0.239.85:3000 - OtterCookie operator server: 147.124.202.205 (ports 7671, 7676, 7679) - Endpoints: /task/mac, /task/tokenlinux Trojanized applications distributed via associated infrastructure: The Unarchiver, Presentify, PDFify, Magic Disk Cleaner, Sketch 2026.2, SiteSucker Pro, RAR Extractor Max, Mp3tag, Mole, HextEdit, Folder Preview Pro, Disk Doctor Pro, ServerCat, Bartender. Malicious file paths: - .macos (hidden executable in app bundle) - Info.plist (modified CFBundleExecutable) - /Library/Application Support/<appname>Extra (PKG preinstall location) - ~/.task/ (staging directory) - preinstall, postinstall (PKG scripts) - tokenlinux.sh (Stage 3 payload) - parser.js (Final OtterCookie payload) Contact/lure channel: t.me/W3PIBot (Telegram)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›