VDB
GCVE-110-OSM-2026-11137
GCVE-110-OSM-2026-11137
Advisory PublishedCVSS 9.6/10
Campaign: NullReceiver
The file contains a benign ESLint config followed by a large obfuscated payload that implements a cryptocurrency-related bot. It uses dynamic requires, network requests to RPC endpoints, and specifically targets Ethereum addresses/transactions for exfiltration to a C2.
This package contains a heavily obfuscated payload disguised as a template `.eslintrc.js` file. The obfuscator.io-obfuscated code (1506 hex-variable matches, whitespace-padded payload concealment) was deobfuscated to reveal 21 IOCs including the domain `h.drpc.org` (classified as fetched-payload), an Ethereum address
`0xa322e5f3d311d3080e6f0121063e9adc2490ef1a` (classified as exfil), and the campaign markers `_0x1c18` (Contagious Interview 2026 / Famous Chollima / UNC5267 / DPRK) and `q4FZkxX{!h,Sr3=@` (nullreceiver / DPRK Lazarus) and `global['_V']` (PolinRider / DPRK Lazarus). The attacker model is consistent with DPRK Contagious Interview operations: a CLI tool that scaffolds backend projects while silently delivering a malicious payload embedded in a template file, using `global['r']=require` aliasing and `stdio: 'ignore'` to suppress detection. The co-occurrence of three distinct DPRK campaign markers, deobfuscated C2 domains, and an Ethereum exfil address constitutes unambiguous confirmation of malicious intent.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | zenntechinc-cli | all (affected) | — |
Browse GCVE Records
3,587 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.