VDB
GCVE-110-OSM-2026-13271
GCVE-110-OSM-2026-13271
Advisory PublishedCVSS 8.8/10
This package presents a clear attacker model: a brand-new npm account (< 1 day old) publishes a package claiming to be a 'solidity gas watcher' but whose entrypoint exports a pino-logger clone API (module.exports.pino), indicating identity masquerade to slip into Solidity/Hardhat toolchains. The critical payload is lib/config.js — a 4.3 MB file with 281,870+ hex escape matches, control-flow flattening (while(!![]){switch}), and execSync calls. The IOC http://192.168.1.42:9200 embedded in the obfuscated blob suggests Elasticsearch data exfil or C2 staging. No source repository exists and the package description is a generic policy template, consistent with a throwaway malware delivery vehicle
lib/config.js:1 is obfuscator.io-obfuscated code in a trojanized pino clone that literally calls execSync() with decoded obfuscated command strings, dynamically requires fs/path/child_process, and spawns detached hidden child processes ('windowsHide':true,'detached':true) — hidden shell execution with no legitimate purpose in a logger whose index.js exports only a no-op middleware. This is second-stage execution/persistence behavior, not a scanner artifact.
## Static analysis (vigil)
Verdict `BLOCK`, score 55/100. Critical/high findings:
- [critical] SC-015 Shell command execution — `package/lib/config.js:1`
- [critical] SC-015 Shell command execution — `package/lib/config.js:1`
- [high] OBF-028 Obfuscator.io string-array rotation — `package/lib/config.js:1`
## Package metadata
- Publisher: unknown
- Published: 2026-10-05T12:26:10.465Z
- Install hooks: none found
- SHA-256 (tarball): `67245e4d4ad4b95d176f47cbda7bd8e1939f6db4af7bc6cd39e158f89c30d69a`
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | solidity-gas-watcher | all (affected) | — |
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.