VDB
GCVE-110-OSM-2026-10856
GCVE-110-OSM-2026-10856
Advisory PublishedCVSS 8.8/10
Package @js-lib-team/env-parser is advertised as an environment-variable parser but on require/import executes a top-level IIFE in index.js that reads the installer's local.env file, extracts values matching PRIVATE_KEY / SECRET / MNEMONIC via a 64-hex regex, and uses those keys to construct ethers.Wallet instances that sign and broadcast transactions transferring native-token balances (ETH/BNB/Polygon/Avalanche and other supported chains) from the installer's wallets to five hardcoded attacker-controlled destination addresses, including 0x70951410C5E9E938D8715288A7229548287a1a62 and bc1q4h4a2sjf4k9quhx7xrajfgcsaz082cv5h3g8dt. The load-time routine also sets process.title to 'systemd: [logrotate]' to disguise the Node process in ps/top output and ships helper stubs labelled 'Process Hiding & Persistence' and 'Polymorphic & Encryption Layers'. The declared parser purpose is a cover story; the actual behavior on module load is theft of installer-owned wallet key material and direct movement of funds to attacker addresses.
When executed, it automatically reads .env, masquerades as a system process, and tries to transfer assets to hard-coded wallets. As written, it is unlikely to complete a transfer because it queries the invalid address SOURCE_WALLET before constructing a transaction.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @js-lib-team/env-parser | all (affected) | — |
Browse GCVE Records
3,587 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.