VDB
GCVE-110-OSM-2026-12362
GCVE-110-OSM-2026-12362
Advisory PublishedCVSS 5.4/10
PolinRider malware infection in Anasarfeen123/poke-ai — developer account/machine compromised, obfuscated payload injected directly into pokemon-showdown/eslint.config.mjs.
=== VICTIM REPO (NON-FORK) ===
Attack type: Direct injection into developer's own repo (not fork/PR based)
Repo: Anasarfeen123/poke-ai
Infected file: pokemon-showdown/eslint.config.mjs
Signature: PolinRider v1 obfuscated payload (rmcej%otb% / _$_1e42 / global['!'] family)
Note: this repo is not a fork — classified Category A (individual victim), not an upstream-injection attempt.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
264 records in the GCVE database · Updated September 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.