VDB
GCVE-110-OSM-2026-9814
GCVE-110-OSM-2026-9814
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
DESTINATION
- custom-c2: gh.ac (primary, plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.ae (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.am (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.aC (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.aE (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.aM (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.gl (plaintext) in dist/cjs/human-readable/runtime/utils.js
- custom-c2: gh.gs (plaintext) in dist/cjs/human-readable/runtime/utils.js
(+13 more)
EXFIL
- Corporate Environment Targeting in dist/cjs/human-readable/runtime/utils.js: "tModifiers, structs, type: 'event', })); return { name: match"
- Corporate Environment Targeting in dist/esm/human-readable/runtime/utils.js: "tModifiers, structs, type: 'event', })); return { name: match"
- Corporate Environment Targeting in src/human-readable/runtime/utils.ts: "tModifiers, structs, type: 'event', }), ) return { name: match"
OBFUSCATION
- Obfuscation: augmented proxied array function replacements in dist/cjs/human-readable/runtime/utils.js
- Obfuscation: augmented proxied array function replacements in dist/esm/exports/index.js
- Obfuscation: obfuscator.io in dist/cjs/human-readable/runtime/utils.js
- Obfuscation: obfuscator.io in dist/esm/exports/index.js
- Decoded Base64 Content in dist/cjs/abis/json.js (x2)
- Decoded Base64 Content in dist/esm/abis/json.js (x2)
- Decoded Base64 Content in dist/types/abis/json.d.ts (x2)
- Decoded Base64 Content in src/abis/json.ts (x2)
(+4 more)
ADDITIONAL FINDINGS
- Dynamic Code Execution in dist/cjs/regex.js: "exec(string)"
- Indirect Function Constructor Access in dist/types/abi.d.ts: "["constructor"]"
- Publisher Has Other Malicious Packages
PAYLOAD FILES
dist/cjs/human-readable/runtime/utils.js (+ dist/cjs/abis/json.js, dist/esm/abis/json.js)
INDICATORS (IOCs)
- urls: https://abitype.dev, https://bestofjs.org/projects/abitype, https://docs.soliditylang.org/en/latest/abi-spec.html, https://eips.ethereum.org/EIPS/eip-712, https://abitype.dev/api/types (+24 more)
- domains: abitype.dev, bestofjs.org, bestofjs-serverless.now.sh, docs.soliditylang.org, eips.ethereum.org (+3 more)
- emails: t@wevm.dev, j@wevm.dev
- payloadFileHash: 5ca8bd72535b6598b46a07740c21e968fd671c0a63572c027a02dc65369d6b79
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @wrenfield/abitype | all (affected) | — |
Aliases
Browse GCVE Records
67,954 records in the GCVE database · Updated August 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.