VDB

GCVE-110-OSM-2026-7476

GCVE-110-OSM-2026-7476
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published June 12, 2026
Malicious Composer/Packagist package 'sevenspan/code-generator' compromised in the PolinRider DPRK-linked supply-chain campaign (Socket threat research). The artifact was published with the campaign's obfuscated loader that fetches and executes a blockchain-hosted second-stage infostealer payload. Part of the PolinRider (DPRK-linked; Contagious Interview / Famous Chollima) supply-chain campaign tracked by Socket. Behavior: obfuscated JavaScript loader planted in the compromised artifact; retrieves an encrypted second-stage payload from blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain), decrypts it with embedded XOR keys, and executes it via eval() for remote code execution and persistence via detached processes. Follow-on payloads: DEV#POPPER, OmniStealer, InvisibleFerret — credential theft, browser-data theft, crypto-wallet exfiltration, keylogging. Propagation: temp_auto_push.bat rewrites git commit history and force-pushes malicious changes to spread across downstream repositories. Code signatures: rmcej%otb% (original) / Cot%3t=shtP (new) markers; decoder functions _$_1e42 / MDy. Malicious git commit reference(s): 2a6736cf0004623af17d510c6af2c784847e8f22, f208b111118c5b2e5a968147deadd3e868e898b6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsevenspan/code-generatordev-feat/livewire-version-update, dev-feat/migration-message, dev-feat/notification-blade-file-support, dev-feat/resource-collection-changes, dev-fix/data-type-mapping, dev-fix/feedback, dev-fix/generator-path-and-migration-table-name, dev-hotfix/vitepress-setup, dev-master, dev-update/notification-modal (affected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›