VDB

GCVE-110-OSM-2026-9566

GCVE-110-OSM-2026-9566
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 31, 2026
A heavily obfuscated file (src/normalize-options.js, 1497 hex-variable identifiers matching obfuscator.io signature) hides a hardcoded IPv4 address that was only recovered through deobfuscation — a PostCSS plugin has zero legitimate reason to embed a raw IP literal in an obfuscated layer. The package was published by a brand-new account (paulmoore_delta, 2 packages total) with a mismatched author name (Alex Rivera vs. npm user Paul Moore), published and rapidly versioned within a single day, all classic supply-chain attack patterns. The attacker model is a dependency-confusion or typosquatting loader: the obfuscated normalize-options.js almost certainly contacts a hardcoded IP at import time for staging or exfiltration. The legitimate postcss/animate.css ecosystem has no relation to this publisher. ENTRY index.js (main: index.js) OBFUSCATION - IOCs Found in Deobfuscated Code in src/normalize-options.js - Obfuscation (osm-deobfuscator): obfuscator-io in src/normalize-options.js - Obfuscation patterns: hexVariables in src/normalize-options.js - recovered 1 ipv4 from decoded/deobfuscated content PAYLOAD FILES src/normalize-options.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpostcss-animate-css-varsall (affected)

Browse GCVE Records

67,893 records in the GCVE database · Updated August 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›