VDB
GCVE-110-OSM-2026-10276
GCVE-110-OSM-2026-10276
Advisory PublishedCVSS 5.4/10
Repository created 2026-07-21 by throwaway account dm1-21726 hosting a malicious Windows Python infostealer bundle (dm1.zip). Distributed via threat actor
infrastructure and reported on Twitter/X by malware researcher @suyog41.
dm1.zip (MD5: 3818b9eb69fef63380c67dfe64b45b18, SHA256: 1d23497fd636d5bee2c8d586694a156e99450a53a78bbffc23e8fce47bb909cf) is a self-contained Windows Python
3.12 runtime bundle classified as Win32.Trojan.Ravartar by ReversingLabs. The malicious entry point is Lib/site-packages/sitecustomize.py, auto-executed on
every Python startup, which uses hex-escaped module names to evade static analysis and runs a base64+zlib-compressed second-stage payload via
exec(zlib.decompress(base64.b64decode(...))). Bundled libraries expose full stealer capabilities: pypsexec+smbprotocol (SMB lateral movement),
spnego+sspilib (Windows credential theft via SSPI/Kerberos), curl_cffi (C2 communication), PyCryptodome+cryptography (data encryption before exfiltration),
pywin32 (Windows API/browser harvesting).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
805 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.