VDB
GCVE-110-OSM-2026-11141
GCVE-110-OSM-2026-11141
Advisory PublishedCVSS 9.6/10
This package was published by DPRK threat actors who have added a JavaScript payload in js/main.js.
Campaign: NullReceiver
The file contains heavily obfuscated JavaScript that implements an Ethereum RPC client used to interact with blockchain nodes. It uses dynamic requirement of 'child_process' and attempts to connect to multiple hardcoded RPC endpoints including h.drpc.org and public.blockscope.info.
This PyPI package contains an obfuscator.io-packed JavaScript file (pybitjs/js/main.js) that, when deobfuscated, yields campaign markers attributed to both the nullreceiver and PolinRider DPRK/Lazarus threat actors — specifically the strings 'q4FZkxX{!h,Sr3=@' and 'global[\'_V\']'. Deobfuscation recovered 21 IOCs including the domain h.drpc.org (a known DPRK-linked RPC endpoint used for cryptocurrency theft), an Ethereum address (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a) classified as an exfil endpoint, and multiple payload-fetching domains. The Python runner (pybitjs/runner.py) uses subprocess.run to execute this obfuscated JS payload, making this a classic Contagious Interview / DPRK supply chain attack pattern where a cryptocurrency-themed PyPI package shells out to a hidden JavaScript stealer. The package has zero legitimate metadata (no description, no repository, no author) confirming a burner/throwaway attacker profile.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | pybitjs | all (affected) | — |
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.