VDB
GCVE-110-OSM-2026-12791
GCVE-110-OSM-2026-12791
Advisory PublishedCVSS 9.6/10
Throwaway Codeberg repository hosting the CHAOS Worm loader chain. Account 'hellscripter' was created 2026-09-29 05:11:09Z and abandoned 15 minutes later at 05:26:34Z after two commits (a606c832f4 'use Web Archive', 5149bfde1d 'first commit'). Serves node.js and linux.sh installer stages consumed by the malicious npm preinstall hooks in the express-javascript / express-nodejs / exprdd typosquat family.
Repository serves the following payloads:
- /raw/branch/main/node.js — SHA256 e255d473e13f6bfb8c594ff5eb459cf1441983fe0424ab2623d79286331fd33d
- /raw/branch/main/linux.sh — SHA256 d6d78ef8ed8bd6d77e1b871e3ce0a0c5e5929af02aee29ba8d94e5067f2aca12 (archived) / 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577 (current)
Installer drops CHAOS RAT SHA256 2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2 as systemd-fontrenderd, beacons to Tor onion s5n2uyo6gb6dhirsm5pihwohi6e7ayrwojx4xjow4cqabmbowpezenid.onion:80.
Delivery uses web.archive.org as a mirror to evade URL blocklists.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.