VDB
GCVE-110-OSM-2026-7843
GCVE-110-OSM-2026-7843
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, obfuscated code.
ENTRY
_cjs/account-abstraction/index.js (default-index: index.js)
LOOT
- Cryptocurrency Wallet Theft in _esm/accounts/generateMnemonic.js: "mnemonic phrase"
- Cryptocurrency Wallet Theft in _esm/accounts/mnemonicToAccount.js: "mnemonic phrase"
- Cryptocurrency Wallet Theft in _esm/actions/wallet/signMessage.js: ".metamask"
- Cryptocurrency Wallet Theft in _esm/actions/wallet/signTypedData.js: ".metamask"
- Cryptocurrency Wallet Theft in _types/accounts/generateMnemonic.d.ts: "mnemonic phrase"
- Cryptocurrency Wallet Theft in _types/accounts/mnemonicToAccount.d.ts: "mnemonic phrase"
- Cryptocurrency Wallet Theft in _types/actions/wallet/signMessage.d.ts: ".metamask"
- Cryptocurrency Wallet Theft in _types/actions/wallet/signTypedData.d.ts: ".metamask"
(+6 more)
DESTINATION
- ethereumAddresses: 0x20c00000000000000000000000000000000000fa (exfil, plaintext)
- ethereumAddresses: 0xFBA3912Ca04dd458c843e2EE08967fC04f3579c2 (exfil, plaintext)
- ethereumAddresses: 0xf39fd6e51aad88f6f4ce6ab8827279cfffb92266 (exfil, plaintext)
- ethereumAddresses: 0x70997970c51812dc3a010c7d01b50e0d17dc79c8 (exfil, plaintext)
- ethereumAddresses: 0xa5cc3c03994DB5b0d9A5eEdD10CabaB0813678AC (exfil, plaintext)
- ethereumAddresses: 0xba5ed110efdba3d005bfc882d75358acbbb85842 (exfil, plaintext)
- ethereumAddresses: 0x0ba5ed0c6aa8c49038f819e587e2633c4a9f428a (exfil, plaintext)
- ethereumAddresses: 0xa46cc63eBF4Bd77888AA327837d20b23A63a56B5 (exfil, plaintext)
(+42 more)
EXFIL
- Corporate Environment Targeting in _types/clients/createTestClient.d.ts: "tMode = 'anvil' | 'hardhat' | 'ganache'; export type TestClientConfig<mode exten..."
- Corporate Environment Targeting in _types/clients/decorators/test.d.ts: "tMode } from '../createTest"
- Corporate Environment Targeting in clients/createTestClient.ts: "tMode = 'anvil' | 'hardhat' | 'ganache' export type TestClientConfig< mode exten..."
- Corporate Environment Targeting in clients/decorators/test.ts: "tMode } from '../createTest"
- Data Encoding for Exfiltration in _cjs/utils/ens/avatar/utils.js: "btoa("
- Data Encoding for Exfiltration in _cjs/utils/rpc/http.js: "btoa("
- Data Encoding for Exfiltration in _esm/utils/ens/avatar/utils.js: "btoa("
- Data Encoding for Exfiltration in _esm/utils/rpc/http.js: "btoa("
(+4 more)
OBFUSCATION
- Dynamic Base64 Decoding in _cjs/utils/ens/avatar/parseAvatarRecord.js: "atob(resolvedNftUri."
- Dynamic Base64 Decoding in _esm/utils/ens/avatar/parseAvatarRecord.js: "atob(resolvedNftUri."
- Dynamic Base64 Decoding in utils/ens/avatar/parseAvatarRecord.ts: "atob(resolvedNftUri."
- Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toCoinbaseSmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..."
- Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toSimple7702SmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..."
- Base64 Encoded Payload in _cjs/account-abstraction/accounts/implementations/toSoladySmartAccount.js: "'0xfffffffffffffffffffffffffffffff0000000000000000000000000000000007aaaaaaaaaaaa..."
- Base64 Encoded Payload in _cjs/actions/public/simulateCalls.js: "'0x6080604052348015600e575f80fd5b5061016d8061001c5f395ff3fe608060405234801561000..."
- Base64 Encoded Payload in _cjs/constants/contracts.js: "'0x608060405234801561001057600080fd5b506115b9806100206000396000f3fe6080604052600..."
(+35 more)
ADDITIONAL FINDINGS
- Suspicious TLD Domain in _cjs/chains/definitions/abstract.js: "https://api.mainnet.abs.xyz"
PAYLOAD FILES
_types/clients/decorators/wallet.d.ts (+ clients/decorators/wallet.ts, _esm/accounts/generateMnemonic.js)
INDICATORS (IOCs)
- urls: https://docs.tempo.xyz/protocol/tips/tip-1009, https://docs.tempo.xyz, https://docs.tempo.xyz/protocol/transactions, https://viem.sh/docs/actions/public/simulateCalls, https://viem.sh/docs/eip7702 (+45 more)
- domains: docs.tempo.xyz, viem.sh, docs.alchemy.com, eips.ethereum.org, docs.optimism.io (+41 more)
- payloadFileHash: e2a8af05343cc741502e431bd5b87e567af0e71e5813fcbaf87d1729ac2d8eed
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @wrenfield/viem | all (affected) | — |
Aliases
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.