VDB
GCVE-110-OSM-2026-1320
GCVE-110-OSM-2026-1320
Advisory PublishedCVSS 8.8/10
Legitimate npm package that was compromised after its maintainer's npm and GitHub accounts were taken over. Four malicious versions (1.2.1, 1.2.2, 1.2.3 and 1.2.4) were published within about 30 minutes on April 2, 2026. They add a dropper that downloads and runs a remote access trojan on Windows, Linux or macOS, giving the attacker command execution, file listing, binary execution and system reconnaissance, plus registry persistence on Windows. Any system that ran the dropper should be treated as fully compromised. The malware and command-and-control behavior match the March 2026 axios npm compromise, which has been attributed to a North Korean threat group, and researchers place both incidents in the same campaign wave.
About the version list: the three earlier releases (1.0.0, 1.0.1 and 1.2.0, published in 2023) predate the attack and were not found to be malicious. Version 1.2.2 contained only an empty test stub in place of the payload, although it was published as part of the same attack. After the incident, npm unpublished every version and replaced the package with a security placeholder. This record is set to all versions because nothing legitimate remains to install, not because every historical release was malicious. Some public advisories list all seven historical versions as malicious, which appears to be a side effect of that takedown. Because the package is now unpublished and unsupported, no version of it should be used.
## Payload 1: setup dropper (stage 1)
Malicious payload found in: `bin/setup.cjs` (added in 1.2.1 as `bin/setup.js` and renamed in 1.2.4 to fix an ES module error). `package.json` and `bin/generate.js` were also modified to run it.
- Trigger: runs when a user runs `mgc-setup` or the new `mgc setup` subcommand. Version 1.2.1 only registered it under the generic `cli` bin name. Version 1.2.2 shipped an empty stub to test delivery. Versions 1.2.3 and 1.2.4 carry the full payload.
- Behavior: detects the operating system and builds a C2 URL from a campaign ID argument that defaults to `gate`, giving `hxxps://admondtamang[.]com[.]np/gate`. The C2 domain is the developer's own personal domain.
- macOS: writes an AppleScript that uses curl to download a binary from the C2 to `/Library/Caches/com.apple.act.mond` (a name mimicking an Apple process), makes it executable and runs it in the background. The request body is `packages[.]npm[.]org/product0`. The mgc binary was not analyzed in the source report. At the same drop path, the axios sample is a compiled C++ Mach-O RAT that supports the same four commands, runs scripts through a temporary AppleScript file and `osascript`, and ad-hoc signs dropped binaries to get past Gatekeeper.
- Windows: copies PowerShell to `%PROGRAMDATA%\wt.exe`, then runs a VBScript that downloads the stage 2 script from the Gist below and executes it hidden with execution policy bypass.
- Linux: downloads the Python RAT to `/tmp/ld.py` and runs it in a loop that restarts it every two seconds.
- Cleanup: deletes itself and `package.json`, then renames `package.md` to `package.json` to restore a clean manifest. All errors are silently swallowed.
- Stage 2 hosting: `hxxps://gist[.]github[.]com/admondtamang/814132e794e5d007e9b8ebd223a9494f`, a Gist created April 1, 2026 on the compromised maintainer's GitHub account. It is no longer available.
## Payload 2: Linux RAT (stage 2)
Malicious payload found in: `linux.payload` (Python, saved as `/tmp/ld.py`)
- Behavior: sends an initial listing of the home, config, Documents and Desktop directories, then beacons about every 20 seconds (the axios Linux sample beacons every 60 seconds) with hostname, username, OS details, timezone, boot time and the full process list.
- Commands from the C2: `kill`, `peinject` (meant to write a base64-decoded binary to a hidden file in /tmp, make it executable and run it, but the handler references an undefined variable and fails as written, as in the axios Linux sample), `runscript` (shell commands or base64-encoded Python) and `rundir` (directory listing).
- C2 protocol: base64-encoded JSON over HTTP POST with the User-Agent `mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0)`.
## Payload 3: Windows RAT (stage 2)
Malicious payload found in: `window.payload` (PowerShell, run through the copied `%PROGRAMDATA%\wt.exe`)
- Persistence: writes a hidden `%PROGRAMDATA%\system.bat` and sets the registry value `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftUpdate` to run it at login. The batch file fetches a fresh payload from the C2 each time, using the request body `packages[.]npm[.]org/product1`.
- Behavior: same C2 protocol, user agent and four commands as the Linux RAT, beaconing about every 60 seconds. `peinject` loads a .NET assembly in memory through reflection (`Extension.SubRoutine.Run2`) instead of writing a file. Directory enumeration also covers OneDrive, AppData\Roaming and every drive root.
## Relationship to the axios compromise
The macOS drop path, the four C2 commands, the `Extension.SubRoutine.Run2` injection, the `packages[.]npm[.]org/product{0,1}` markers and the User-Agent match the WAVESHAPER.V2 backdoor documented in the axios compromise, which is attributed to the North Korean group UNC1069 (also tracked as BlueNoroff and TA444). The macOS path, a C2 URL passed as a command-line argument and the uncommon User-Agent also appear in the earlier WAVESHAPER backdoor attributed to the same group. The Windows persistence and the broken Linux `peinject` handler are also present in the axios samples.
Differences: the axios dropper used campaign ID `6202033` and a dedicated C2 server, while this one defaults to `gate` and uses the victim's own domain and Gist. No infrastructure is shared with the axios compromise, so the link rests on the malware and its behavior.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | mgc | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.