VDB

GCVE-110-OSM-2026-8332

GCVE-110-OSM-2026-8332
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 18, 2026
Malicious package detected. Behaviors: obfuscated code. ENTRY bin/autoprefixer (bin: bin/autoprefixer) OBFUSCATION - Decoded Base64 Content in lib/autoprefixer.js (x3) - Dynamic Base64 Decoding in lib/autoprefixer.js: "Buffer.from(prefixPrettier, 'base64')" - Deobfuscation Failed in lib/autoprefixer.js - recovered 2 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Silent Process Execution in lib/autoprefixer.js: "{silent: true" - Very New NPM Publisher Account PAYLOAD FILES lib/autoprefixer.js INDICATORS (IOCs) - urls: https://autoprefixer.github.io/, https://caniuse.com/, https://cultofmartians.com/tasks/autoprefixer-grid.html, https://caniuse.com/mdn-css_selectors_backdrop, https://opencollective.com/postcss/ (+3 more) - domains: sitnik.es, postcss.github.io, evilmartians.com, autoprefixer.github.io, caniuse.com (+4 more) - emails: andrey@sitnik.es - payloadFileHash: 62fcef4c2a7f6b277912c92ba62bca6d0f7f7fd2ea89ff913672518a4eaea8b9

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@ai_/autoprefixersall (affected)

References

vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›