VDB
GCVE-110-OSM-2026-4720
GCVE-110-OSM-2026-4720
Advisory PublishedCVSS 9.6/10
Sophisticated npm typosquatting supply chain attack combining fake 15-year git history forgery with cryptocurrency theft malware. Attacker created throwaway account 'tamekacooke21' on 2026-04-23, generated fabricated git history spanning 2011-2026 in just 28 minutes, and distributed malware through npm package 'events-channel' that mimics the popular Node.js 'events' module. Git forensics analysis reveals massive timestamp discrepancy between claimed commit dates (2011-2026) and actual repository push time (2026-04-23T16:10:34Z), indicating sophisticated history rewriting attack designed to establish false legitimacy.
## C2 infrastructure
This package shares campaign C2 infrastructure with other Graphalgo packages confirmed by JFrog Security Research. The campaign C2 chain uses Ethereum Sepolia smart contract `0xE390863Dac96a7118C71227C2b099B50cF602D31` as an encrypted dead-drop, with X25519 ECDH key exchange using hardcoded TA public key `bad013df6eec5d686f4cc8551e0a5c87a0135164bdd1dafb1c75141d1b526702`. Exfiltration uses Slack channel `C0B8XPGCKQS` (bot token embedded in payload) and Telegram chat `-1003952553968` via bot `8961878831`. A second-stage Slack polling agent (channel `C0B8GEPFMK9`) provides persistent remote command execution via AES-GCM/PBKDF2-encrypted operator messages.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | events-channel | 2.4.1 (affected), all (affected) | — |
Browse GCVE Records
346 records in the GCVE database · Updated September 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.