VDB

GCVE-110-OSM-2026-12269

GCVE-110-OSM-2026-12269
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 15, 2026
This package is published by a victim developer account whose GitHub organization (visanduma) was compromised by the DPRK PolinRider campaign in mid-June 2026. The intrusion was carried out through the LaHiRu contributor account, a developer who was themselves a victim of PolinRider malware and whose account was used without their knowledge to introduce the malicious commits. The package itself has over 700,000 cumulative downloads. Malicious code was introduced into four development branches (dev-nova4support, dev-main, dev-using-inertia, dev-nova5); no stable release has been identified as malicious at the time of writing. Because Packagist can resolve code directly from Git repositories, malicious source already planted in a repository becomes available through the registry without requiring the attacker to steal publishing credentials. Consumers of development branches directly are at risk. PolinRider's primary objective is cryptocurrency theft; the delivered infostealer also captures credentials, source code, and other data accessible to the infected developer environment. Malicious JavaScript is concealed in files named tailwind.config.js — a build-tool configuration file developers are less likely to inspect during code review. A new PHP execution technique was also identified in this intrusion: heavily obfuscated JavaScript was inserted directly into index.php and launched via PHP's shell_exec function, allowing a PHP entry point to initiate the JavaScript infection chain without relying on VS Code task execution. The JavaScript payload resolves C2 infrastructure using the NullReceiver technique: it monitors Ethereum wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a for outbound transactions and decodes recipient address bytes to obtain the current C2 IP. Next-stage payloads are fetched from the resolved server. Observed C2 IPs: 193[.]247[.]144[.]38, 166[.]88[.]73[.]46, 166[.]88[.]134[.]62, 23[.]27[.]13[.]135. SHA-256 hashes (payload files, all masquerading as tailwind.config.js): - 7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9 - b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3 - ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395 - 139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683 - 515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownvisanduma/nova-two-factordev-nova4support; dev-main; dev-using-inertia; dev-nova5 (affected)

Browse GCVE Records

374 records in the GCVE database · Updated September 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›