VDB

GCVE-110-OSM-2026-13271

GCVE-110-OSM-2026-13271
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 5, 2026
This package presents a clear attacker model: a brand-new npm account (< 1 day old) publishes a package claiming to be a 'solidity gas watcher' but whose entrypoint exports a pino-logger clone API (module.exports.pino), indicating identity masquerade to slip into Solidity/Hardhat toolchains. The critical payload is lib/config.js — a 4.3 MB file with 281,870+ hex escape matches, control-flow flattening (while(!![]){switch}), and execSync calls. The IOC http://192.168.1.42:9200 embedded in the obfuscated blob suggests Elasticsearch data exfil or C2 staging. No source repository exists and the package description is a generic policy template, consistent with a throwaway malware delivery vehicle lib/config.js:1 is obfuscator.io-obfuscated code in a trojanized pino clone that literally calls execSync() with decoded obfuscated command strings, dynamically requires fs/path/child_process, and spawns detached hidden child processes ('windowsHide':true,'detached':true) — hidden shell execution with no legitimate purpose in a logger whose index.js exports only a no-op middleware. This is second-stage execution/persistence behavior, not a scanner artifact. ## Static analysis (vigil) Verdict `BLOCK`, score 55/100. Critical/high findings: - [critical] SC-015 Shell command execution — `package/lib/config.js:1` - [critical] SC-015 Shell command execution — `package/lib/config.js:1` - [high] OBF-028 Obfuscator.io string-array rotation — `package/lib/config.js:1` ## Package metadata - Publisher: unknown - Published: 2026-10-05T12:26:10.465Z - Install hooks: none found - SHA-256 (tarball): `67245e4d4ad4b95d176f47cbda7bd8e1939f6db4af7bc6cd39e158f89c30d69a`

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsolidity-gas-watcherall (affected)—

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›