VDB
GCVE-110-OSM-2026-1820
GCVE-110-OSM-2026-1820
Advisory PublishedCVSS 9.6/10
Malicious Obfuscated code located in the repository code file.
The main difference, this script is using base64 encoded JS file instead of using obfuscated JS attacks that we are seeing in Polinrider campaign.
Base64 encoded payload in the gptlint.ts file that talks to known Aptos and Tron addresses identified in Polinrider campaign.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Malicious package:
advisory
Browse GCVE Records
74,352 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.