VDB
GCVE-110-OSM-2026-12495
GCVE-110-OSM-2026-12495
Advisory PublishedCVSS 5.4/10
PolinRider malware infection in shareeq-acc/network-load-balancer-from-scratch - developer account/machine compromised, obfuscated payload injected directly into public/fonts/fa-solid-400.woff2, using the previously-undocumented global.i="A#-" marker variant.
=== VICTIM REPO (NON-FORK) ===
Attack type: Direct injection into developer's own repo (not fork/PR based)
Repo: shareeq-acc/network-load-balancer-from-scratch
Infected file: public/fonts/fa-solid-400.woff2
Signature: global.i="A#-..." marker variant (javascript-obfuscator.io-style hex/opcode packing, internally remaps to global['_V'])
Note: this repo is not a fork - classified Category A (individual victim), not an upstream-injection attempt.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
Browse GCVE Records
400 records in the GCVE database · Updated September 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.