VDB

GCVE-110-OSM-2026-4720

GCVE-110-OSM-2026-4720
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 25, 2026
Sophisticated npm typosquatting supply chain attack combining fake 15-year git history forgery with cryptocurrency theft malware. Attacker created throwaway account 'tamekacooke21' on 2026-04-23, generated fabricated git history spanning 2011-2026 in just 28 minutes, and distributed malware through npm package 'events-channel' that mimics the popular Node.js 'events' module. Git forensics analysis reveals massive timestamp discrepancy between claimed commit dates (2011-2026) and actual repository push time (2026-04-23T16:10:34Z), indicating sophisticated history rewriting attack designed to establish false legitimacy. ## C2 infrastructure This package shares campaign C2 infrastructure with other Graphalgo packages confirmed by JFrog Security Research. The campaign C2 chain uses Ethereum Sepolia smart contract `0xE390863Dac96a7118C71227C2b099B50cF602D31` as an encrypted dead-drop, with X25519 ECDH key exchange using hardcoded TA public key `bad013df6eec5d686f4cc8551e0a5c87a0135164bdd1dafb1c75141d1b526702`. Exfiltration uses Slack channel `C0B8XPGCKQS` (bot token embedded in payload) and Telegram chat `-1003952553968` via bot `8961878831`. A second-stage Slack polling agent (channel `C0B8GEPFMK9`) provides persistent remote command execution via AES-GCM/PBKDF2-encrypted operator messages.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownevents-channel2.4.1 (affected), all (affected)

References

vendor

Browse GCVE Records

346 records in the GCVE database · Updated September 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›