VDB
GCVE-110-OSM-2026-10504
GCVE-110-OSM-2026-10504
Advisory PublishedCVSS 9.6/10
This package directly depends on 'bcs-mini', which is confirmed malicious per the knownMalware finding. The publisher account 'graypin' published both packages within the same session (npmAccountAge < 1 day, earliest publish timestamps seconds apart), indicating a coordinated campaign where sui-gql-lite serves as a delivery vector for the malicious bcs-mini dependency. The entrypoint immediately requires bcs-mini via `require('bcs-mini')` and calls `uleb128Decode`, ensuring the malicious dependency executes on import. The package itself presents as a plausible, well-written GraphQL client for the Sui blockchain (complete with real endpoint mystenlabs.com) to establish legitimacy and encourage installation, while the actual payload is laundered through the dependency. No repository, brand-new account, and a security holding flag that was recovered all corroborate adversarial intent.
ENTRY
index.js (main: index.js)
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
- Brand New Package
- Very New NPM Publisher Account
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | sui-gql-lite | all (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.