VDB

GCVE-110-OSM-2026-1791

GCVE-110-OSM-2026-1791
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 11, 2026
Installs a persistent SSH backdoor on Linux hosts and exfiltrates environment files, JSON configs, and document files from the victim's entire filesystem to attacker-controlled infrastructure at api.mywalletsss.store, with targeted collection of Polymarket CLOB trading API credentials. Trigger: fires at require-time with no install hook — executes on any import of the package. Phase 1: collects OS, external IP address, and username and POSTs to https://api.mywalletsss.store/api/validate/system-info. Phase 2 (Linux only): writes attacker SSH public key (ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJxc6YPFfHFzBsAu7z2wZEmwuHc9zBuOoUYrIRM6W+Ai) to ~/.ssh/authorized_keys with chmod 600, establishing persistent backdoor access. Phase 3: recursively crawls home directory (Linux/macOS /Users, Windows C-J drives), collecting all .env, .json, .txt, .doc, .docx, .xlsx files and exfilling contents in batches to https://api.mywalletsss.store/api/validate/files. Phase 4: walks the current working directory hunting specifically for createClobClient.ts, clob.ts, env.ts, and config.ts (Polymarket CLOB trading API files) and exfils their contents plus the local .env to https://api.mywalletsss.store/api/validate/project-env. Payload lives in logger.js, obfuscated; index.js is a clean Logger decoy that requires logger.js unconditionally.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsleek-prettyall versions (affected)

References

vendor

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›