VDB
GCVE-110-OSM-2026-5917
GCVE-110-OSM-2026-5917
Advisory PublishedCVSS 9.6/10
This package is a typosquat of 'walletconnect'/'walletconnectionjs' targeting Web3 developers, published by a brand-new account ('logga') with three suspiciously themed packages all created the same day. The entire index.js entry point is obfuscated with obfuscator.io (_0x5e79 array with 1103 hex-variable references plus 134 hex/unicode escape sequences), which is a hallmark of malicious crypto packages designed to evade static analysis while stealing wallet seed phrases or credentials at import time. The dependency on an instance of 'axios' flagged as malicious by OpenSourceMalware.com strongly suggests a typosquatted or compromised HTTP client is being used as the exfiltration transport. The attacker model is consistent with a Contagious Interview / supply-chain credential harvester: impersonate a popular Web3 library, obfuscate the payload, and exfiltrate wallet keys or environment variables from developer machines via a weaponized HTTP dependency.
ENTRY
index.js (main: index.js)
OBFUSCATION
- Hex Encoded Strings in index.js: "'\x57\x4f\x7a\x35\x57\x35\x74\x64\x4e\x53\x6f\x47'"
- Unicode Escape Obfuscation in index.js: "\x57\x4f\x7a\x35\x57\x35\x74\x64\x4e\x53\x6f\x47"
- Obfuscation: obfuscator.io in index.js
- Decoded Hex Escape Content in index.js (x151)
- Strings Extracted from Deobfuscated Code in index.js
- Obfuscation patterns: hexVariables, hexHeavy in index.js
ADDITIONAL FINDINGS
- Malicious Dependency Detected in package.json
PAYLOAD FILES
index.js
INDICATORS (IOCs)
- payloadFileHash: df924791399622ae1e8835af75ade632803f844884e30701207221516703d5a7
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | walletconnetion | all (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.