VDB
GCVE-110-OSM-2026-10776
GCVE-110-OSM-2026-10776
Advisory PublishedCVSS 5.4/10
The package has a burner-like metadata profile, with no description, no repository, and only minimal package fields, which is weak but real suspicion. More importantly, the recovered IOCs include a passive RPC endpoint (`https://eth.llamarpc.com`) and a set of high-trust Ethereum addresses marked as `exfil`, which suggests the code may be collecting or routing blockchain-related data rather than acting as a normal contracts library. I cannot prove an explicit attacker model from the provided evidence, but the combination of minimal metadata and multiple exfil-classified blockchain addresses is not consistent with a clearly benign utility. Treat this as suspicious and review the package contents before trusting it in a supply-chain path.
DESTINATION
- 9 exfil (ethereumAddresses)
(values recorded in verified_iocs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | neutrl-contracts | all (affected) | — |
Aliases
Browse GCVE Records
3,528 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.