VDB

GCVE-110-OSM-2026-12685

GCVE-110-OSM-2026-12685
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 28, 2026
On require() of img-to-native, index.js reads banner.jpg from the.cache directory of its sole dependency cdn-img-fetch, locates a payload appended after the PNG IEND marker, base64-decodes it, and AES-256-CBC decrypts it using a key derived from sha256('nif-runtime-2027'). The decrypted bytes are written to %LOCALAPPDATA%\Programs\NodeRuntime\node_runtime_helper.exe with mode 0o755, and the source image is then unlinked. An fs.watch fallback waits for the image to appear if it is not yet staged. The payload is obfuscated (hidden after a PNG end-of-image marker, base64-encoded, AES-encrypted), unverified (no hash or signature check), and dropped to a persistence-adjacent path with executable bits set. The advertised purpose ("convert image files to native binary representation") does not require decrypting content appended after a PNG IEND chunk to materialize a Windows executable. The companion package cdn-img-fetch is pinned as a caret range (^1.0.0), so future 1.x releases can silently change the delivered payload bytes. Installing or loading this package results in attacker-controlled code being written to the installer's filesystem with execute permission. ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownimg-to-nativeall (affected)—

References

advisory
vendor

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›