VDB
GCVE-110-OSM-2026-11984
GCVE-110-OSM-2026-11984
Advisory PublishedCVSS 8.8/10
Part of a mass campaign run from GitHub account tesssmax (id 301410327) spanning 2026-07-21 to 2026-09-08 across dozens of repositories (installer2-installer49, minus gaps). This repo's GitHub Release asset is a fake installer/dropper that, once run, silently installs a ScreenConnect RMM client renamed to disguise itself as "Feedback Tool" (Windows service FeedbackToolSvc_NN), which phones home to www.somtinn.com:8041 (ScreenConnect instance ID 008c4a1933454b9c) as a Guest session, giving the operator full remote access (screen share, file manager, backstage shell). The dropper self-elevates, extracts an embedded MSI+EXE+HTA bundle, runs a silent msiexec install, then rewrites the Windows Uninstall registry DisplayName/Publisher to "Feedback Tool" to hide from Add/Remove Programs. The exact same payload file is reused byte-for-byte across multiple differently-branded repos in this campaign, indicating a templated build pipeline rather than bespoke per-target malware. See github.com/tesssmax/installer47 (OSM threat_id 15a928c5-8a9a-4364-af60-e112aaf26e0f) for a related, previously-reported sibling in this same campaign.
Malicious payload found in: GitHub Release asset "Docusign" (sha256:ec0420244f1e3dcdeaa8dba44e0a4f876e6ba000b1432f0dbc1e9ce06b5b7785)
Self-elevating dropper extracts an embedded ScreenConnect MSI installer, a secondary EXE, and two mshta HTA files (fake progress + fake success UI skinned to the impersonated brand). Runs `msiexec /i setup.msi /quiet /norestart` then `setup.exe /S` to silently install ScreenConnect, then uses PowerShell to rename the resulting Uninstall registry entries to "Feedback Tool".
C2 connection string: ?e=Access&y=Guest&h=www.somtinn.com&p=8041&k=<RSA key material>
ScreenConnect instance ID: 008c4a1933454b9c
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
506 records in the GCVE database · Updated September 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.