VDB

GCVE-110-OSM-2026-12467

GCVE-110-OSM-2026-12467
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 17, 2026
This is a DPRK Contagious Interview style malicious NPM package that installs the OtterCookie malware which is an infostealer and cryptostealer with persistence. It uses the NullReceiver technique to hide its second stage payload. ENTRY src/index.js (main: src/index.js) DESTINATION - 8 fetched-payload (deobfuscated) (values recorded in verified_iocs) OBFUSCATION - IOCs Found in Deobfuscated Code in src/index.js - Obfuscation: augmented proxied array function replacements in src/index.js - Obfuscation (osm-deobfuscator): NiceGUI Multi-layer Obfuscation in src/index.js - String Array Obfuscation in src/index.js: "['eth_blockN','_process',':443/0x/cl','olKrM','BtmBu','LUUcK','h.blocksco','http..." - Obfuscation patterns: hexVariables in src/index.js - recovered 1 ipv4, 2 urls, 8 domains, 8 _domainCandidates from decoded/deobfuscated content ADDITIONAL FINDINGS - Global Require Alias in src/index.js: "global['r']=require" - Dynamic Code Execution in scripts/release-channel.js: "exec(version)" - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES src/index.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntailwindcss-contact-formall (affected)

Browse GCVE Records

400 records in the GCVE database · Updated September 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›