VDB
GCVE-110-OSM-2026-7961
GCVE-110-OSM-2026-7961
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, install-time execution.
ENTRY
dist/index.min.js (install-hook: node dist/index.min.js)
- Install Hook Executes Local JS File in package.json
PERSISTENCE
- Startup Persistence in dist/index.js: ".bashrc"
DESTINATION
- reconstructed: https://api.telegram.org/bot${...}/sendMessage (primary, reconstructed)
- custom-c2: api.telegram.org (reconstructed) in dist/index.js
- telegram-bot: api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/sendMessage`, (plaintext) in dist/index.js
- custom-c2: https://cloudflare-eth.com (plaintext) in dist/index.js
- custom-c2: https://blockchain.info/pushtx (plaintext) in dist/index.js
- custom-c2: https://api.mainnet-beta.solana.com (plaintext) in dist/index.js
- custom-c2: cloudflare-eth.com (plaintext) in dist/index.js
- custom-c2: api.mainnet-beta.solana.com (plaintext) in dist/index.js
EXFIL
- Sensitive File Access in dist/index.js: "'.ssh/id_rsa'"
- Network Request in dist/index.js: "axios.post("
- System Information Collection in dist/index.js: "os.userInfo()"
OBFUSCATION
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Chai-Max Wallet Theft Indicators in .env.example: "SOLANA_WALLET"
- Dynamic Code Execution in dist/index.js: "exec(text)"
- Shell Command Execution in dist/index.js: "child_process').exec"
- Suspicious URL Pattern in Template Literal in dist/index.js: "https://api.telegram.org/bot${...}/sendMessage"
PAYLOAD FILES
dist/index.js
INDICATORS (IOCs)
- emails: dev@eth-provider.org
- payloadFileHash: 9d4b79c061cd8c15ee537289283ac84918e0e2ce27a36255c07d0605080205a6
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @web3-helpers/core | all (affected) | — |
Aliases
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.