VDB
GCVE-110-OSM-2026-13259
GCVE-110-OSM-2026-13259
Advisory PublishedCVSS 8.8/10
Malicious npm package containing an obfuscated PowerShell loader that retrieves and executes a remote second-stage payload and exfiltrates process information.
The package contains ten identical obfuscated PowerShell payload files disguised with document, image, and text extensions. The loader hides the console, decodes an embedded XOR/Base64 stage, repeatedly downloads an HTTPS response from the confirmed C2 endpoint, extracts a PNG-appended rotated gzip payload, decompresses it in memory, and executes it via ScriptBlock dot-sourcing. It then enumerates running process names and executable paths, serializes them as JSON, and repeatedly POSTs the data to the same endpoint. The verified retrieval attempt returned an empty response; the remote second-stage behavior remains unresolved.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | serpacksven1 | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.