VDB

GCVE-110-OSM-2026-13376

GCVE-110-OSM-2026-13376
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 3, 2026
This tool is a Windows based infostealer. It steals browser credentials, cookies, payment-card data, Discord tokens, gaming sessions, Telegram data, and cryptocurrency-wallet files, then uploads the collected archive to a Discord webhook. Git Warden confirmed this repository as malicious by static analysis of its source code. The code was read, never executed. The malicious code sits in the file a2.py around line 1328. The code reads the saved account store of a Minecraft launcher (the vanilla launcher, Lunar Client, Feather Client or the Essential mod). Those files hold refresh and access tokens for the victim's Microsoft account, so copying them lets the attacker sign in as the victim. No legitimate project ships code like this. The repository was either compromised or purpose-built to deliver malware to anyone who clones or installs it. The evidence references link the exact file and line of each finding, and the payload description names every detection rule that fired, so a reviewer can open the repository and verify each one independently. Git Warden found this repository by searching GitHub for code that matches a confirmed malware signature: "launcher_accounts.json" "api/webhooks". The malicious payload sits in a2.py at line 1328. The code reads the saved account store of a Minecraft launcher (the vanilla launcher, Lunar Client, Feather Client or the Essential mod). Those files hold refresh and access tokens for the victim's Microsoft account, so copying them lets the attacker sign in as the victim. Detection rules that fired in this repository: code_execution/py-system (1 file), credential_access/mc-launcher-accounts (1 file), network_exfil/discord-webhook (1 file).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)—

Browse GCVE Records

3,310 records in the GCVE database · Updated October 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›