VDB

GCVE-110-OSM-2026-13426

GCVE-110-OSM-2026-13426
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 30, 2026
Repository compromised with an XMRig cryptominer committed on 2026-08-30 under the disguised message 'fix(subtask) 修改OpenAI版本', followed by GhostAction secret-exfiltration workflows pushed on 2026-09-15. Malicious payload found in: Dockerfile, run.sh Dockerfile downloads XMRig 6.21.0 (base64-encoded URL), UPX-packed, installed as /usr/local/bin/pyworker; hidden copy at /tmp/.<hash>. run.sh adds a start_service function; persistence via fake health_check job every 45 seconds; state in /var/run/devops.pid and /var/log/devops.log. Mining config XOR-encrypted in SERVICE_CONFIG env var (XOR key: devops2024) pointing to pool.supportxmr.com:3333. Monero wallet: 832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL GhostAction workflows: github_actions_security.yml, security-check.yml

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)—

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›