VDB

GCVE-110-OSM-2026-12541

GCVE-110-OSM-2026-12541
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 23, 2026
This repository is part of a GitHub Actions-based download inflation farm operated by the Graphalgo campaign. Repositories in this farm run automated workflows on every push that decrypt an AES-256-GCM-encrypted target list (key: `npm_workvr_protect_key_v1`, embedded in a bundled WASM file with MD5 `91e020c13cb97a6365135b53b0d0fe5f`), resolve npm tarball URLs for the campaign's malicious packages, and download each one a specified number of times at one-second intervals — discarding the bytes immediately. This manufactured download traffic (tens of millions of downloads per package) was used to make newly published malicious packages appear popular and trustworthy. All repositories receive byte-identical `commands.json` pushes from a central orchestrator.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

346 records in the GCVE database · Updated September 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›