VDB
GCVE-110-OSM-2026-7097
GCVE-110-OSM-2026-7097
Advisory PublishedCVSS 8.8/10
Malicious package detected. Behaviors: data exfiltration, code execution.
ENTRY
dist/src/index.js (main: dist/src/index.js)
EXFIL
- System Information Collection in dist/src/index.js: "process.platform"
OBFUSCATION
- Decoded Base64 Content in dist/src/index.js
ADDITIONAL FINDINGS
- Shell Command Execution in dist/src/index.js: "require('child_process')"
- Silent Process Execution in dist/src/index.js: "stdio: 'ignore'"
- Detached Child Process Payload in dist/src/index.js: "spawn( process.execPath, ["-e", code], { stdio: "ignore", detached: true"
- Very New NPM Publisher Account
- Rapid Version Publishing
PAYLOAD FILES
dist/src/index.js
INDICATORS (IOCs)
- urls: https://hardhat.org
- domains: hardhat.org
- payloadFileHash: cd71ef0b5bb72a19467131a4400973556100430d6beed325859d605bee4d348e
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | hardhat-compile-ethers | 0.4.12 (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.