VDB
GCVE-110-OSM-2026-7893
GCVE-110-OSM-2026-7893
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
dist/index.cjs (main: dist/index.cjs)
LOOT
- Cryptocurrency Wallet Theft in dist/index.cjs: ".metamask"
- Cryptocurrency Wallet Theft in dist/index.esm.js: ".metamask"
- Cryptocurrency Wallet Theft in dist/wallets/metamask/styles.css: ".metamask"
DESTINATION
- custom-c2: https://wagmirequest.la (primary, plaintext) in dist/index.cjs
- custom-c2: https://www.riveanimation.cards/v1 (plaintext) in dist/index.cjs
- custom-c2: https://api.wagmiwallet.org (plaintext) in dist/index.cjs
- custom-c2: https://www.riveanimation.cards (plaintext) in dist/index.cjs
- custom-c2: https://ipapi.co/ip/ (plaintext) in dist/index.cjs
- custom-c2: https://support.metamask.io (plaintext) in dist/index.cjs
- custom-c2: https://www.riveanimation.cards/v7/images/flag.mp4 (plaintext) in dist/index.cjs
- custom-c2: https://jquery.org/license (plaintext) in dist/index.cjs
(+24 more)
EXFIL
- Data Encoding for Exfiltration in dist/index.cjs: "encodeURIComponent( key"
- Data Encoding for Exfiltration in dist/index.esm.js: "encodeURIComponent( key"
- Network Request in dist/index.cjs: "fetch('https:"
- Network Request in dist/index.esm.js: "fetch('https:"
OBFUSCATION
- Unicode Escape Obfuscation in dist/index.cjs: "\u8BF7\u8F93\u5165\u5BC6\u7801\u89E3\u9501\u94B1\u5305"
- Unicode Escape Obfuscation in dist/index.esm.js: "\u8BF7\u8F93\u5165\u5BC6\u7801\u89E3\u9501\u94B1\u5305"
ADDITIONAL FINDINGS
- Dynamic Code Execution in dist/index.cjs: "exec( selector )"
PAYLOAD FILES
dist/index.cjs (+ dist/index.esm.js)
INDICATORS (IOCs)
- ipv6: 4::, FBC::, d::, D::, f:: (+2 more)
- urls: https://wagmirequest.la\, https://www.riveanimation.cards/v1\, https://api.wagmiwallet.org\, https://www.riveanimation.cards\, https://www.riveanimation.cards/v1/images/logo/metamask-fox.png\ (+28 more)
- domains: tailwindcss.com, fonts.cdnfonts.com, 7.ET
- payloadFileHash: a0a01bacfba38008711c9e126e2fdb92e381d2b2428a600a255b1580a89033af
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ddok-modal | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.