VDB

GCVE-110-OSM-2026-11824

GCVE-110-OSM-2026-11824
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 9, 2026
Repository compromised by the PolinRider DPRK threat actor (Lazarus / Contagious Interview cluster). PolinRider is an obfuscated JavaScript payload appended to legitimate config or source files, using v1 markers (_$_1e42 decoder + rmcej%otb% signature + shuffle seed 2857687) or v2 markers (global.i="A(8|9|10|11)-" injection prefix + shuffle seed 1111436 + Cot%3t=shtP marker). The payload uses a string-array shuffle decoder plus a require() hijack via global assignment, then fetches a second-stage loader. Detected via OpenSourceMalware.com PolinRider GitHub hunt (2026-09-08). Repository contains the PolinRider decoder signature in 1 file(s). Injected paths: postcss.config.mjs. Content verification confirmed hex-obfuscated identifier patterns and PolinRider magic seeds in the payload where inspected. Attribution: DPRK / Lazarus / Contagious Interview campaign. Malware family: PolinRider (v1 and v2 obfuscator variants).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

556 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›