VDB
GCVE-110-OSM-2026-12400
GCVE-110-OSM-2026-12400
Advisory PublishedCVSS 8.8/10
PolinRider malware (v3 variant: javascript-obfuscator.io hex packing, global['r']/global['m'] require/module hijack) injected via an ACTIVE OPEN PR into next.config.js of kinde-starter-kits/kinde-nextjs-app-router-starter-kit, part of a Kinde auth-as-a-service org-wide pattern (5 confirmed infected PRs across kinde-oss and kinde-starter-kits orgs, 3 different committer accounts) - consistent with a compromised shared scaffolding tool/template or multiple compromised collaborator accounts, not a single isolated incident.
=== UPSTREAM INJECTION ATTEMPT (ACTIVE OPEN PR, PART OF ORG-WIDE PATTERN) ===
Attack type: Compromised-collaborator/shared-template PR injection
Target repo: kinde-starter-kits/kinde-nextjs-app-router-starter-kit
Author: onderay
PR created: 2026-05-25T05:31:51Z
=== PAYLOAD ===
Infected file: next.config.js
Signature: PolinRider v3-style - javascript-obfuscator.io hex/opcode packing, global['r']=require;global['m']=module hijack, global['_V']=global['i'] marker, blockchain-RPC-based C2, spawn+eval execution
=== RELATED FINDINGS (same session) ===
kinde-oss/js-utils PR #268 (dtoxvanilla1991) - same payload, submitted separately as critical
4 other kinde-oss/kinde-starter-kits PRs also confirmed infected - see OSM for linked reports
=== PR STATUS ===
Open, not merged. Parent infected: No (near miss, but live).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
Browse GCVE Records
264 records in the GCVE database · Updated September 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.