VDB

GCVE-110-OSM-2026-11137

GCVE-110-OSM-2026-11137
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 26, 2026
Campaign: NullReceiver The file contains a benign ESLint config followed by a large obfuscated payload that implements a cryptocurrency-related bot. It uses dynamic requires, network requests to RPC endpoints, and specifically targets Ethereum addresses/transactions for exfiltration to a C2. This package contains a heavily obfuscated payload disguised as a template `.eslintrc.js` file. The obfuscator.io-obfuscated code (1506 hex-variable matches, whitespace-padded payload concealment) was deobfuscated to reveal 21 IOCs including the domain `h.drpc.org` (classified as fetched-payload), an Ethereum address `0xa322e5f3d311d3080e6f0121063e9adc2490ef1a` (classified as exfil), and the campaign markers `_0x1c18` (Contagious Interview 2026 / Famous Chollima / UNC5267 / DPRK) and `q4FZkxX{!h,Sr3=@` (nullreceiver / DPRK Lazarus) and `global['_V']` (PolinRider / DPRK Lazarus). The attacker model is consistent with DPRK Contagious Interview operations: a CLI tool that scaffolds backend projects while silently delivering a malicious payload embedded in a template file, using `global['r']=require` aliasing and `stdio: 'ignore'` to suppress detection. The co-occurrence of three distinct DPRK campaign markers, deobfuscated C2 domains, and an Ethereum exfil address constitutes unambiguous confirmation of malicious intent.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownzenntechinc-cliall (affected)

References

vendor

Browse GCVE Records

3,587 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›