VDB
GCVE-110-OSM-2026-13426
GCVE-110-OSM-2026-13426
Advisory PublishedCVSS 8.8/10
Repository compromised with an XMRig cryptominer committed on 2026-08-30 under the disguised message 'fix(subtask) 修改OpenAI版本', followed by GhostAction secret-exfiltration workflows pushed on 2026-09-15.
Malicious payload found in: Dockerfile, run.sh
Dockerfile downloads XMRig 6.21.0 (base64-encoded URL), UPX-packed, installed as /usr/local/bin/pyworker; hidden copy at /tmp/.<hash>.
run.sh adds a start_service function; persistence via fake health_check job every 45 seconds; state in /var/run/devops.pid and /var/log/devops.log.
Mining config XOR-encrypted in SERVICE_CONFIG env var (XOR key: devops2024) pointing to pool.supportxmr.com:3333.
Monero wallet: 832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL
GhostAction workflows: github_actions_security.yml, security-check.yml
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.