VDB

GCVE-110-OSM-2026-8019

GCVE-110-OSM-2026-8019
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 14, 2026
The package itself appears functionally legitimate — index.js contains a clean, readable multi-chain address validator with no network calls, obfuscation, or credential access. However, the publisher 'solbuilder_io' (email: angel_lopez89@proton.me) has a confirmed critical-severity malicious package already in OSM (eth-wallet-helpers, threat ID 50199fc3-5496-4410-8855-ac0a0a4afcdb), and maintains a portfolio of 10 packages with crypto/blockchain naming that closely resembles the pattern of a threat actor seeding plausible-looking utility packages alongside malicious ones. The package was published just 1 day ago with a single version and no download history, consistent with a freshly planted dependency confusion or supply chain staging artifact. While this version's code is clean, the publisher context warrants caution — this could be a benign package used to establish credibility or a payload that has not yet been activated. ENTRY index.js (main: index.js) ADDITIONAL FINDINGS - Publisher Has Other Malicious Packages

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@solbuilder_io/crypto-validator1.0.0 (affected)

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›