VDB

GCVE-110-OSM-2026-7843

GCVE-110-OSM-2026-7843
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 14, 2026
Malicious package detected. Behaviors: data exfiltration, obfuscated code. ENTRY _cjs/account-abstraction/index.js (default-index: index.js) LOOT - Cryptocurrency Wallet Theft in _esm/accounts/generateMnemonic.js: "mnemonic phrase" - Cryptocurrency Wallet Theft in _esm/accounts/mnemonicToAccount.js: "mnemonic phrase" - Cryptocurrency Wallet Theft in _esm/actions/wallet/signMessage.js: ".metamask" - Cryptocurrency Wallet Theft in _esm/actions/wallet/signTypedData.js: ".metamask" - Cryptocurrency Wallet Theft in _types/accounts/generateMnemonic.d.ts: "mnemonic phrase" - Cryptocurrency Wallet Theft in _types/accounts/mnemonicToAccount.d.ts: "mnemonic phrase" - Cryptocurrency Wallet Theft in _types/actions/wallet/signMessage.d.ts: ".metamask" - Cryptocurrency Wallet Theft in _types/actions/wallet/signTypedData.d.ts: ".metamask" (+6 more) DESTINATION - ethereumAddresses: 0x20c00000000000000000000000000000000000fa (exfil, plaintext) - ethereumAddresses: 0xFBA3912Ca04dd458c843e2EE08967fC04f3579c2 (exfil, plaintext) - ethereumAddresses: 0xf39fd6e51aad88f6f4ce6ab8827279cfffb92266 (exfil, plaintext) - ethereumAddresses: 0x70997970c51812dc3a010c7d01b50e0d17dc79c8 (exfil, plaintext) - ethereumAddresses: 0xa5cc3c03994DB5b0d9A5eEdD10CabaB0813678AC (exfil, plaintext) - ethereumAddresses: 0xba5ed110efdba3d005bfc882d75358acbbb85842 (exfil, plaintext) - ethereumAddresses: 0x0ba5ed0c6aa8c49038f819e587e2633c4a9f428a (exfil, plaintext) - ethereumAddresses: 0xa46cc63eBF4Bd77888AA327837d20b23A63a56B5 (exfil, plaintext) (+42 more) EXFIL - Corporate Environment Targeting in _types/clients/createTestClient.d.ts: "tMode = 'anvil' | 'hardhat' | 'ganache'; export type TestClientConfig<mode exten..." - Corporate Environment Targeting in _types/clients/decorators/test.d.ts: "tMode } from '../createTest" - Corporate Environment Targeting in clients/createTestClient.ts: "tMode = 'anvil' | 'hardhat' | 'ganache' export type TestClientConfig< mode exten..." - Corporate Environment Targeting in clients/decorators/test.ts: "tMode } from '../createTest" - Data Encoding for Exfiltration in _cjs/utils/ens/avatar/utils.js: "btoa(" - Data Encoding for Exfiltration in _cjs/utils/rpc/http.js: "btoa(" - Data Encoding for Exfiltration in _esm/utils/ens/avatar/utils.js: "btoa(" - Data Encoding for Exfiltration in _esm/utils/rpc/http.js: "btoa(" (+4 more) OBFUSCATION - Dynamic Base64 Decoding in _cjs/utils/ens/avatar/parseAvatarRecord.js: "atob(resolvedNftUri." - Dynamic Base64 Decoding in _esm/utils/ens/avatar/parseAvatarRecord.js: "atob(resolvedNftUri." - Dynamic Base64 Decoding in utils/ens/avatar/parseAvatarRecord.ts: "atob(resolvedNftUri." - Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toCoinbaseSmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..." - Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toSimple7702SmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..." - Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toSoladySmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..." - Base64 Encoded Payload in _cjs/actions/public/simulateCalls.js: "'0x6080604052348015600e575f80fd5b5061016d8061001c5f395ff3fe608060405234801561000..." - Base64 Encoded Payload in _cjs/constants/contracts.js: "'0x608060405234801561001057600080fd5b506115b9806100206000396000f3fe6080604052600..." (+35 more) ADDITIONAL FINDINGS - Suspicious TLD Domain in _cjs/chains/definitions/abstract.js: "https://api.mainnet.abs.xyz" PAYLOAD FILES _types/clients/decorators/wallet.d.ts (+ clients/decorators/wallet.ts, _esm/accounts/generateMnemonic.js) INDICATORS (IOCs) - urls: https://docs.tempo.xyz/protocol/tips/tip-1009, https://docs.tempo.xyz, https://docs.tempo.xyz/protocol/transactions, https://viem.sh/docs/actions/public/simulateCalls, https://viem.sh/docs/eip7702 (+45 more) - domains: docs.tempo.xyz, viem.sh, docs.alchemy.com, eips.ethereum.org, docs.optimism.io (+41 more) - payloadFileHash: e2a8af05343cc741502e431bd5b87e567af0e71e5813fcbaf87d1729ac2d8eed

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@wrenfield/viemall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›