VDB
GCVE-110-OSM-2026-9566
GCVE-110-OSM-2026-9566
Advisory PublishedCVSS 9.6/10
A heavily obfuscated file (src/normalize-options.js, 1497 hex-variable identifiers matching obfuscator.io signature) hides a hardcoded IPv4 address that was only recovered through deobfuscation — a PostCSS plugin has zero legitimate reason to embed a raw IP literal in an obfuscated layer. The package was published by a brand-new account (paulmoore_delta, 2 packages total) with a mismatched author name (Alex Rivera vs. npm user Paul Moore), published and rapidly versioned within a single day, all classic supply-chain attack patterns. The attacker model is a dependency-confusion or typosquatting loader: the obfuscated normalize-options.js almost certainly contacts a hardcoded IP at import time for staging or exfiltration. The legitimate postcss/animate.css ecosystem has no relation to this publisher.
ENTRY
index.js (main: index.js)
OBFUSCATION
- IOCs Found in Deobfuscated Code in src/normalize-options.js
- Obfuscation (osm-deobfuscator): obfuscator-io in src/normalize-options.js
- Obfuscation patterns: hexVariables in src/normalize-options.js
- recovered 1 ipv4 from decoded/deobfuscated content
PAYLOAD FILES
src/normalize-options.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | postcss-animate-css-vars | all (affected) | — |
Browse GCVE Records
67,893 records in the GCVE database · Updated August 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.