VDB
GCVE-110-OSM-2026-5653
GCVE-110-OSM-2026-5653
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, install-time execution.
Entrypoint: scripts/postinstall.js (install-hook: node scripts/postinstall.js)
Exfil: 8227918239:AAGEMDrBZluDsBBYPxfSyMuv2l3FY8cZCcs (telegram-bot, recovery: plaintext in src/index.js)
Payload: src/index.js
Key findings:
- Cryptocurrency Wallet Theft in src/index.js: "'/.ethereum"
- Install Hook Executes Local JS File in package.json: ""postinstall": "node scripts/postinstall.js""
- Platform Detection with Data Collection in src/index.js: "JSON.stringify({ chat_id: CHAT_ID, text: msg, parse_mode: 'HTML' });
const o..."
IOCs:
- telegramBots: 8227918239:AAGEMDrBZluDsBBYPxfSyMuv2l3FY8cZCcs
- payloadFileHash: c43afad949027040c6414d26fa4eea6e2671d2572f9df7fd595e12baf204854f
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ethereum-kit-9 | all (affected) | — |
Aliases
Browse GCVE Records
74,352 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.