VDB

GCVE-110-OSM-2026-13259

GCVE-110-OSM-2026-13259
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 5, 2026
Malicious npm package containing an obfuscated PowerShell loader that retrieves and executes a remote second-stage payload and exfiltrates process information. The package contains ten identical obfuscated PowerShell payload files disguised with document, image, and text extensions. The loader hides the console, decodes an embedded XOR/Base64 stage, repeatedly downloads an HTTPS response from the confirmed C2 endpoint, extracts a PNG-appended rotated gzip payload, decompresses it in memory, and executes it via ScriptBlock dot-sourcing. It then enumerates running process names and executable paths, serializes them as JSON, and repeatedly POSTs the data to the same endpoint. The verified retrieval attempt returned an empty response; the remote second-stage behavior remains unresolved.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownserpacksven1all (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›