VDB
GCVE-110-OSM-2026-13269
GCVE-110-OSM-2026-13269
Advisory PublishedCVSS 5.4/10
Publisher 'naorya' has a confirmed malicious package (css-eqxcdx-polyfill) already reported in OSM, and this package is one of many similarly-named css-*-polyfill placeholders published by the same brand-new account within a single day. The naming pattern — randomized hex-string suffixes on fake CSS polyfill names — is consistent with dependency confusion or namespace squatting campaigns. No code findings are present (likely an empty placeholder), but the publisher's established malicious history and the pattern of bulk publishing make this package highly suspect. The '@naorya/registry-override-repro' package name in the same account further signals an explicit interest in registry manipulation attacks.
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-fxgiix-polyfill | all (affected) | — |
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.