VDB

GCVE-110-OSM-2026-7961

GCVE-110-OSM-2026-7961
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, install-time execution. ENTRY dist/index.min.js (install-hook: node dist/index.min.js) - Install Hook Executes Local JS File in package.json PERSISTENCE - Startup Persistence in dist/index.js: ".bashrc" DESTINATION - reconstructed: https://api.telegram.org/bot${...}/sendMessage (primary, reconstructed) - custom-c2: api.telegram.org (reconstructed) in dist/index.js - telegram-bot: api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/sendMessage`, (plaintext) in dist/index.js - custom-c2: https://cloudflare-eth.com (plaintext) in dist/index.js - custom-c2: https://blockchain.info/pushtx (plaintext) in dist/index.js - custom-c2: https://api.mainnet-beta.solana.com (plaintext) in dist/index.js - custom-c2: cloudflare-eth.com (plaintext) in dist/index.js - custom-c2: api.mainnet-beta.solana.com (plaintext) in dist/index.js EXFIL - Sensitive File Access in dist/index.js: "'.ssh/id_rsa'" - Network Request in dist/index.js: "axios.post(" - System Information Collection in dist/index.js: "os.userInfo()" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Chai-Max Wallet Theft Indicators in .env.example: "SOLANA_WALLET" - Dynamic Code Execution in dist/index.js: "exec(text)" - Shell Command Execution in dist/index.js: "child_process').exec" - Suspicious URL Pattern in Template Literal in dist/index.js: "https://api.telegram.org/bot${...}/sendMessage" PAYLOAD FILES dist/index.js INDICATORS (IOCs) - emails: dev@eth-provider.org - payloadFileHash: 9d4b79c061cd8c15ee537289283ac84918e0e2ce27a36255c07d0605080205a6

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@web3-helpers/coreall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›