VDB

GCVE-110-OSM-2026-10504

GCVE-110-OSM-2026-10504
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 15, 2026
This package directly depends on 'bcs-mini', which is confirmed malicious per the knownMalware finding. The publisher account 'graypin' published both packages within the same session (npmAccountAge < 1 day, earliest publish timestamps seconds apart), indicating a coordinated campaign where sui-gql-lite serves as a delivery vector for the malicious bcs-mini dependency. The entrypoint immediately requires bcs-mini via `require('bcs-mini')` and calls `uleb128Decode`, ensuring the malicious dependency executes on import. The package itself presents as a plausible, well-written GraphQL client for the Sui blockchain (complete with real endpoint mystenlabs.com) to establish legitimacy and encourage installation, while the actual payload is laundered through the dependency. No repository, brand-new account, and a security holding flag that was recovered all corroborate adversarial intent. ENTRY index.js (main: index.js) ADDITIONAL FINDINGS - Malicious Dependency Detected in package.json - Brand New Package - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsui-gql-liteall (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›