VDB
GCVE-110-OSM-2026-10136
GCVE-110-OSM-2026-10136
Advisory PublishedCVSS 9.6/10
This package is a typosquat or supply-chain poisoning attempt that masquerades as an Ethereum utility library while unconditionally executing the known-malicious dependency 'commonjs-assertion' via a bare require() call in dist/index.js. The entrypoint explicitly contains `require("commonjs-assertion")` with no conditional logic, ensuring the malicious payload runs on every import. The package is brand new (12 hours old), has no repository, and is self-described as a 'security holding package' — a description that belies its actual contents. The combination of a confirmed-malicious dependency, active invocation in the entrypoint, fresh publication with no history, and an Ethereum address IOC classified as 'exfil' role is unambiguous: the attacker model is supply-chain compromise delivering a known malware payload to consumers of Ethereum tooling packages.
ENTRY
dist/index.js (main: dist/index.js)
DESTINATION
- 1 exfil (ethereumAddresses)
(values recorded in verified_iocs)
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
- Brand New Package
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | eth-library-toolkit | all (affected) | — |
Aliases
Browse GCVE Records
69,369 records in the GCVE database · Updated August 25, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.