VDB
GCVE-110-OSM-2026-13376
GCVE-110-OSM-2026-13376
Advisory PublishedCVSS 8.8/10
This tool is a Windows based infostealer. It steals browser credentials, cookies, payment-card data, Discord tokens, gaming sessions, Telegram data, and cryptocurrency-wallet files, then uploads the collected archive to a Discord webhook.
Git Warden confirmed this repository as malicious by static analysis of its source code. The code was read, never executed. The malicious code sits in the file a2.py around line 1328. The code reads the saved account store of a Minecraft launcher (the vanilla launcher, Lunar Client, Feather Client or the Essential mod). Those files hold refresh and access tokens for the victim's Microsoft account, so copying them lets the attacker sign in as the victim. No legitimate project ships code like this. The repository was either compromised or purpose-built to deliver malware to anyone who clones or installs it. The evidence references link the exact file and line of each finding, and the payload description names every detection rule that fired, so a reviewer can open the repository and verify each one independently. Git Warden found this repository by searching GitHub for code that matches a confirmed malware signature: "launcher_accounts.json" "api/webhooks".
The malicious payload sits in a2.py at line 1328. The code reads the saved account store of a Minecraft launcher (the vanilla launcher, Lunar Client, Feather Client or the Essential mod). Those files hold refresh and access tokens for the victim's Microsoft account, so copying them lets the attacker sign in as the victim. Detection rules that fired in this repository: code_execution/py-system (1 file), credential_access/mc-launcher-accounts (1 file), network_exfil/discord-webhook (1 file).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,310 records in the GCVE database · Updated October 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.