VDB

GCVE-110-OSM-2026-8018

GCVE-110-OSM-2026-8018
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 14, 2026
The package code itself is clean — a straightforward RPC health checker with no obfuscation, no credential theft, no exfiltration, and no install hooks. The IOCs are all legitimate public blockchain RPC endpoints. However, the publisher 'solbuilder_io' has a confirmed malicious package (eth-wallet-helpers, severity critical) already reported in OSM, and operates a portfolio of 10 crypto/blockchain-themed packages, a pattern consistent with a threat actor seeding multiple packages to establish legitimacy or widen attack surface. The account is brand-new with no age data and this package was published one day ago with a single version. While this specific package appears benign on code inspection, the publisher context warrants monitoring — the actor may be establishing trust before injecting malicious logic in a future version or a sibling package. ENTRY index.js (main: index.js) ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages INDICATORS (IOCs) - urls: https://api.mainnet-beta.solana.com, https://eth.llamarpc.com, https://bsc-dataseed.binance.org, https://api.avax.network/ext/bc/C/rpc - domains: api.mainnet-beta.solana.com, eth.llamarpc.com, bsc-dataseed.binance.org, api.avax.network

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@solbuilder_io/rpc-health1.0.0 (affected)

Browse GCVE Records

75,801 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›