VDB
GCVE-110-OSM-2026-12177
GCVE-110-OSM-2026-12177
Advisory PublishedCVSS 9.6/10
Repository distributes an obfuscated cross-platform information stealer disguised as a dry-run cryptocurrency trading application. The application automatically collects credentials, wallet material, browser passwords, messaging sessions, developer secrets, password-manager data, notes, and shell history, then exfiltrates collected files to an attacker-controlled HTTPS service.
Malicious payload found in: dry-only/momentum-desk-linux-arm64.zip (momentum-desk-linux-arm64), with corresponding Linux x64, macOS x64/arm64, and Windows x64 builds.
The packaged Node.js application schedules a hidden collection module approximately 10 seconds after startup. Unless PSM_RAN already equals 1, it launches concurrent collectors and recursively scans files for private keys, seed phrases, AWS secrets, API credentials, and npm/GitHub/PyPI tokens. Additional routines collect shell histories, Telegram Desktop tdata sessions, Chromium-family saved passwords, OneNote/Apple Notes/Sticky Notes/Notion data, SSH and cloud configuration, Solana and desktop-wallet files, and 1Password/Bitwarden/KeePass data. Windows browser-password handling includes DPAPI and AES-256-GCM decryption logic. Collected files and generated artifacts are uploaded as multipart form data with username, platform, timestamps, and collection metadata.
Obfuscated endpoint form: "https://" + "pm-tradi" + "ng-servi" + "ce.verce" + "l.app"; the decoded endpoint is listed in verified_iocs. PSM_API_URL and legacy DFC_API_URL can override the destination.
The macOS helper removes quarantine attributes and ad-hoc signs the application. The README instructs Windows users to bypass SmartScreen. Linux packages include optional systemd persistence requiring manual installation.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | Default branch commit 097859f15cc74255608ae4a2f7ea62a846f6fb49 (affected) | — |
References
Browse GCVE Records
386 records in the GCVE database · Updated September 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.