VDB

GCVE-110-OSM-2026-11141

GCVE-110-OSM-2026-11141
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 26, 2026
This package was published by DPRK threat actors who have added a JavaScript payload in js/main.js. Campaign: NullReceiver The file contains heavily obfuscated JavaScript that implements an Ethereum RPC client used to interact with blockchain nodes. It uses dynamic requirement of 'child_process' and attempts to connect to multiple hardcoded RPC endpoints including h.drpc.org and public.blockscope.info. This PyPI package contains an obfuscator.io-packed JavaScript file (pybitjs/js/main.js) that, when deobfuscated, yields campaign markers attributed to both the nullreceiver and PolinRider DPRK/Lazarus threat actors — specifically the strings 'q4FZkxX{!h,Sr3=@' and 'global[\'_V\']'. Deobfuscation recovered 21 IOCs including the domain h.drpc.org (a known DPRK-linked RPC endpoint used for cryptocurrency theft), an Ethereum address (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a) classified as an exfil endpoint, and multiple payload-fetching domains. The Python runner (pybitjs/runner.py) uses subprocess.run to execute this obfuscated JS payload, making this a classic Contagious Interview / DPRK supply chain attack pattern where a cryptocurrency-themed PyPI package shells out to a hidden JavaScript stealer. The package has zero legitimate metadata (no description, no repository, no author) confirming a burner/throwaway attacker profile.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpybitjsall (affected)

References

vendor

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›