VDB

GCVE-110-OSM-2026-7132

GCVE-110-OSM-2026-7132
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 2, 2026
Git Warden confirmed this GitHub repository as malicious through static analysis of its source code, which means the repository was read and never executed. The malicious code was found in the file webpack.config.js around line 54. The code reaches into credential files such as private keys or cloud configuration in order to steal authentication material. An ordinary, trustworthy project would not contain this, so the finding is a strong and dependable indication that the repository was either compromised or was built from the start to deliver malware to anyone who clones or installs it. The exact file, the line number, and the detection rule that matched are included in the evidence reference so a reviewer can open the repository and confirm all of it independently. The malicious payload is located in webpack.config.js at line 54. The code reaches into credential files such as private keys or cloud configuration in order to steal authentication material.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›