VDB
GCVE-110-OSM-2026-12559
GCVE-110-OSM-2026-12559
Advisory PublishedCVSS 5.4/10
This repository is part of a GitHub Actions-based download inflation farm operated by the Graphalgo campaign. Repositories in this farm run automated workflows on every push that decrypt an AES-256-GCM-encrypted target list (key: `npm_workvr_protect_key_v1`, embedded in a bundled WASM file with MD5 `91e020c13cb97a6365135b53b0d0fe5f`), resolve npm tarball URLs for the campaign's malicious packages, and download each one a specified number of times at one-second intervals — discarding the bytes immediately. This manufactured download traffic (tens of millions of downloads per package) was used to make newly published malicious packages appear popular and trustworthy. All repositories receive byte-identical `commands.json` pushes from a central orchestrator.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
346 records in the GCVE database · Updated September 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.