VDB
GCVE-110-OSM-2026-8019
GCVE-110-OSM-2026-8019
Advisory PublishedCVSS 5.4/10
The package itself appears functionally legitimate — index.js contains a clean, readable multi-chain address validator with no network calls, obfuscation, or credential access. However, the publisher 'solbuilder_io' (email: angel_lopez89@proton.me) has a confirmed critical-severity malicious package already in OSM (eth-wallet-helpers, threat ID 50199fc3-5496-4410-8855-ac0a0a4afcdb), and maintains a portfolio of 10 packages with crypto/blockchain naming that closely resembles the pattern of a threat actor seeding plausible-looking utility packages alongside malicious ones. The package was published just 1 day ago with a single version and no download history, consistent with a freshly planted dependency confusion or supply chain staging artifact. While this version's code is clean, the publisher context warrants caution — this could be a benign package used to establish credibility or a payload that has not yet been activated.
ENTRY
index.js (main: index.js)
ADDITIONAL FINDINGS
- Publisher Has Other Malicious Packages
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @solbuilder_io/crypto-validator | 1.0.0 (affected) | — |
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.