VDB

GCVE-110-OSM-2026-13269

GCVE-110-OSM-2026-13269
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 6, 2026
Publisher 'naorya' has a confirmed malicious package (css-eqxcdx-polyfill) already reported in OSM, and this package is one of many similarly-named css-*-polyfill placeholders published by the same brand-new account within a single day. The naming pattern — randomized hex-string suffixes on fake CSS polyfill names — is consistent with dependency confusion or namespace squatting campaigns. No code findings are present (likely an empty placeholder), but the publisher's established malicious history and the pattern of bulk publishing make this package highly suspect. The '@naorya/registry-override-repro' package name in the same account further signals an explicit interest in registry manipulation attacks. ADDITIONAL FINDINGS - Brand New Package - Very New NPM Publisher Account - Publisher Has Other Malicious Packages

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncss-fxgiix-polyfillall (affected)—

References

vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›