VDB

GCVE-110-OSM-2026-4832

GCVE-110-OSM-2026-4832
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published May 27, 2026
Suspicious package detected. Entrypoint: lib/cjs/index.js (main: ./lib/cjs/index.js) IOCs: - ipv4: 1.101.3.4 - urls: https://academy.warp.cc/docs/sdk/advanced/plugins/deployment, http://nyc-1.dev.arweave.net:1984/, https://dre-1.warp.cc/contract, https://gw.warp.cc, https://links.ethers.org/v5-errors- (+7 more) - domains: academy.warp.cc, indutny.com, t.work, r.work, tree.ge (+10 more) - emails: fedor@indutny.com, feross@feross.org, github@spam.raszi.hu - ethereumAddresses: 0x0000000000000000000000000000000000000000 - sha256Hashes: e60fce93b59e9ec53011aabc21c23e97b2a31369b87a5ae9c44ee89e2a6dec0a, f7e3507399e595929db99f34f57937101296891e44d23f0be1f32cce69616821, 8282263212c609d9ea2a6e3e172de238d8c39cabd5ac1ca10646e23fd5f51508, 11f8a8098557dfe45e8256e830b60ace62d613ac2f7b17bed31b6eaff6e26caf, 175e159f728b865a72f99cc6c6fc846de0b93833fd2222ed73fce5b551e5b739 (+45 more)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownweavedb-warp-contracts-plugin-deployall (affected)

Browse GCVE Records

74,147 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›