VDB

GCVE-110-OSM-2026-9636

GCVE-110-OSM-2026-9636
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 4, 2026
This package is an unambiguous credential and cryptocurrency wallet stealer. The postinstall.js executes on npm install and collects system info, SSH private keys, .npmrc, .gitconfig, browser cookies/login data, crypto wallet directory presence (.metamask, .exodus, .bitcoin, .ethereum, .solana, etc.), and a broad set of CI/cloud environment variables (AWS keys, GitHub tokens, mnemonics, private keys). All collected data is exfiltrated via dual channels: primary to Telegram bot, and backup HTTP POST to attacker-controlled serveo tunnel \. The package name '@zzzgenesis00/crypto-config' is a burner namespace with no metadata, no repository, and claims authorship of 'lorenwest' (the node-config maintainer) as a likely social engineering lure targeting crypto developers. ENTRY postinstall.js (install-hook: node postinstall.js) - Install Hook Executes Local JS File in package.json LOOT - Cryptocurrency Wallet Theft in postinstall.js: ".metamask" DESTINATION - 2 exfil (telegram-bot, custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in postinstall.js: "encodeURIComponent(msg.substring(0, 3800" - Git Configuration Access in postinstall.js: ".gitconfig" ADDITIONAL FINDINGS - Chai-Max Wallet Theft Indicators in postinstall.js: ".exodus" - Shell Command Execution in postinstall.js: "require('child_process')" PAYLOAD FILES postinstall.js TELEGRAM THREAT-ACTOR INTELLIGENCE (live API enrichment): Bot @Test20131_Bot (id 7231970337)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@zzzgenesis00/crypto-configall (affected)

References

advisory
vendor

Browse GCVE Records

67,407 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›