VDB
GCVE-110-OSM-2026-11852
GCVE-110-OSM-2026-11852
Advisory PublishedCVSS 9.6/10
Repository compromised by the PolinRider DPRK threat actor (Lazarus / Contagious Interview cluster). PolinRider is an obfuscated JavaScript payload appended to legitimate config or source files, using v1 markers (_$_1e42 decoder + rmcej%otb% signature + shuffle seed 2857687) or v2 markers (global.i="A(8|9|10|11)-" injection prefix + shuffle seed 1111436 + Cot%3t=shtP marker). The payload uses a string-array shuffle decoder plus a require() hijack via global assignment, then fetches a second-stage loader.
Detected via OpenSourceMalware.com PolinRider GitHub hunt (2026-09-08). Repository contains the PolinRider decoder signature in 1 file(s). Injected paths: src/routes/adminRoute.js. Content verification confirmed hex-obfuscated identifier patterns and PolinRider magic seeds in the payload where inspected. Attribution: DPRK / Lazarus / Contagious Interview campaign. Malware family: PolinRider (v1 and v2 obfuscator variants).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.