VDB

GCVE-110-OSM-2026-12791

GCVE-110-OSM-2026-12791
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 29, 2026
Throwaway Codeberg repository hosting the CHAOS Worm loader chain. Account 'hellscripter' was created 2026-09-29 05:11:09Z and abandoned 15 minutes later at 05:26:34Z after two commits (a606c832f4 'use Web Archive', 5149bfde1d 'first commit'). Serves node.js and linux.sh installer stages consumed by the malicious npm preinstall hooks in the express-javascript / express-nodejs / exprdd typosquat family. Repository serves the following payloads: - /raw/branch/main/node.js — SHA256 e255d473e13f6bfb8c594ff5eb459cf1441983fe0424ab2623d79286331fd33d - /raw/branch/main/linux.sh — SHA256 d6d78ef8ed8bd6d77e1b871e3ce0a0c5e5929af02aee29ba8d94e5067f2aca12 (archived) / 65f0a95b24e30305146346cbc2452cfabadab9e1ca35053e1134b67c38919577 (current) Installer drops CHAOS RAT SHA256 2c9dbc14809f1e1aebda114194368b002acf74c8760b88fc101f625d179793c2 as systemd-fontrenderd, beacons to Tor onion s5n2uyo6gb6dhirsm5pihwohi6e7ayrwojx4xjow4cqabmbowpezenid.onion:80. Delivery uses web.archive.org as a mirror to evade URL blocklists.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)—

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›