VDB
GCVE-110-OSM-2026-10778
GCVE-110-OSM-2026-10778
Advisory PublishedCVSS 5.4/10
This package has a burner-like metadata profile, with no description, no repository, and only minimal package fields, which is often seen in throwaway or staged uploads. The only concrete network indicator is a passive RPC endpoint, `https://eth.llamarpc.com`, and the recovered Ethereum addresses are not by themselves proof of theft or exfiltration. However, the presence of multiple `ethereumAddresses` marked as `exfil` and a zero address alongside minimal metadata is consistent with a crypto-drainer or wallet-related malicious workflow, even though the code body is not shown here. I would treat this as suspicious pending code review rather than confirmed malicious because the attacker model is plausible but not directly demonstrated in the available evidence.
DESTINATION
- 3 exfil (ethereumAddresses)
(values recorded in verified_iocs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | plp-contract | all (affected) | — |
Aliases
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.