VDB
GCVE-110-OSM-2026-9024
GCVE-110-OSM-2026-9024
Advisory PublishedCVSS 5.4/10
Suspicious package detected. Behaviors: obfuscated code.
ENTRY
lib/index.js (main: lib/index.js)
DESTINATION
- ethereumAddresses: 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045 (exfil, plaintext)
- ethereumAddresses: 0x0000000000000000000000000000000000000000 (exfil, plaintext)
OBFUSCATION
- Obfuscation patterns: unicodeHeavy, hexHeavy in lib/index.js
INDICATORS (IOCs)
- domains: ethereum.org
- emails: fabian@ethereum.org, samuel@ethereum.org
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | eth-slint | all (affected) | — |
Aliases
Browse GCVE Records
75,974 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.