VDB

GCVE-110-OSM-2026-12399

GCVE-110-OSM-2026-12399
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published May 25, 2026
PolinRider malware (v3 variant: javascript-obfuscator.io hex packing, global['r']/global['m'] require/module hijack) injected via an ACTIVE OPEN PR into babel.config.js of kinde-starter-kits/kinde-react-native-starter-kit-0-6x, part of a Kinde auth-as-a-service org-wide pattern (5 confirmed infected PRs across kinde-oss and kinde-starter-kits orgs, 3 different committer accounts) - consistent with a compromised shared scaffolding tool/template or multiple compromised collaborator accounts, not a single isolated incident. === UPSTREAM INJECTION ATTEMPT (ACTIVE OPEN PR, PART OF ORG-WIDE PATTERN) === Attack type: Compromised-collaborator/shared-template PR injection Target repo: kinde-starter-kits/kinde-react-native-starter-kit-0-6x Author: onderay PR created: 2026-05-25T05:32:46Z === PAYLOAD === Infected file: babel.config.js Signature: PolinRider v3-style - javascript-obfuscator.io hex/opcode packing, global['r']=require;global['m']=module hijack, global['_V']=global['i'] marker, blockchain-RPC-based C2, spawn+eval execution === RELATED FINDINGS (same session) === kinde-oss/js-utils PR #268 (dtoxvanilla1991) - same payload, submitted separately as critical 4 other kinde-oss/kinde-starter-kits PRs also confirmed infected - see OSM for linked reports === PR STATUS === Open, not merged. Parent infected: No (near miss, but live).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

264 records in the GCVE database · Updated September 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›