VDB
GCVE-110-OSM-2026-1791
GCVE-110-OSM-2026-1791
Advisory PublishedCVSS 8.8/10
Installs a persistent SSH backdoor on Linux hosts and exfiltrates environment files, JSON configs, and document files from the victim's entire filesystem to attacker-controlled infrastructure at api.mywalletsss.store, with targeted collection of Polymarket CLOB trading API credentials.
Trigger: fires at require-time with no install hook — executes on any import of the package. Phase 1: collects OS, external IP address, and username and POSTs to https://api.mywalletsss.store/api/validate/system-info. Phase 2 (Linux only): writes attacker SSH public key (ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJxc6YPFfHFzBsAu7z2wZEmwuHc9zBuOoUYrIRM6W+Ai) to ~/.ssh/authorized_keys with chmod 600, establishing persistent backdoor access. Phase 3: recursively crawls home directory (Linux/macOS /Users, Windows C-J drives), collecting all .env, .json, .txt, .doc, .docx, .xlsx files and exfilling contents in batches to https://api.mywalletsss.store/api/validate/files. Phase 4: walks the current working directory hunting specifically for createClobClient.ts, clob.ts, env.ts, and config.ts (Polymarket CLOB trading API files) and exfils their contents plus the local .env to https://api.mywalletsss.store/api/validate/project-env. Payload lives in logger.js, obfuscated; index.js is a clean Logger decoy that requires logger.js unconditionally.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | sleek-pretty | all versions (affected) | — |
Browse GCVE Records
74,237 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.