VDB

GCVE-110-OSM-2026-10276

GCVE-110-OSM-2026-10276
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 12, 2026
Repository created 2026-07-21 by throwaway account dm1-21726 hosting a malicious Windows Python infostealer bundle (dm1.zip). Distributed via threat actor infrastructure and reported on Twitter/X by malware researcher @suyog41. dm1.zip (MD5: 3818b9eb69fef63380c67dfe64b45b18, SHA256: 1d23497fd636d5bee2c8d586694a156e99450a53a78bbffc23e8fce47bb909cf) is a self-contained Windows Python 3.12 runtime bundle classified as Win32.Trojan.Ravartar by ReversingLabs. The malicious entry point is Lib/site-packages/sitecustomize.py, auto-executed on every Python startup, which uses hex-escaped module names to evade static analysis and runs a base64+zlib-compressed second-stage payload via exec(zlib.decompress(base64.b64decode(...))). Bundled libraries expose full stealer capabilities: pypsexec+smbprotocol (SMB lateral movement), spnego+sspilib (Windows credential theft via SSPI/Kerberos), curl_cffi (C2 communication), PyCryptodome+cryptography (data encryption before exfiltration), pywin32 (Windows API/browser harvesting).

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

805 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›