VDB

GCVE-110-OSM-2026-11953

GCVE-110-OSM-2026-11953
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 9, 2026
Hosts BifrostWallet.exe, a trojanized crypto wallet installer that silently installs a ScreenConnect RMM client configured to phone home to bbdots.com:8041 (ScreenConnect instance ID 6d833e57e5a31c6a) as a Guest session, giving the operator full remote access. Published by the same GitHub account (tesssmax, id 301410327) that later ran a much larger 46-repo campaign using a DIFFERENT ScreenConnect C2 (www.somtinn.com, instance 008c4a1933454b9c, disguised as "Feedback Tool") starting 12 days after this repo. Different C2 domain, different ScreenConnect instance ID, and no "Feedback Tool" disguise branding found in this sample, so it is tracked as a separate/earlier operation rather than folded into that campaign's IOC set. Malicious payload found in: GitHub Release asset "BifrostWallet.exe" (sha256:f8cd736a531c65cce00a01fab875cb2cc350b4561e6eaa643fb46d1b62cb3ba7) NSIS-packed Electron installer unpacks to a ScreenConnect MSI configured with: ?e=Access&y=Guest&h=bbdots.com&p=8041&k=<RSA key material> ScreenConnect instance ID: 6d833e57e5a31c6a

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

506 records in the GCVE database · Updated September 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›