VDB
GCVE-110-OSM-2026-10636
GCVE-110-OSM-2026-10636
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code.
DESTINATION
- discord-webhook: discord.com/api/webhooks/1493402683556761752/veHRFKpZ1UGm13xuS2NdBKgn7QPaKRH-OcQerHufSzCBYZrrOK9uGqyHUODSJULbrWj9 (primary, decoded) in regwin/main.py
- custom-c2: https://discord.com/api/webhooks/1493402683556761752/veHRFKpZ1UGm13xuS2NdBKgn7QPaKRH-OcQerHufSzCBYZrrOK9uGqyHUODSJULbrWj9 (decoded) in regwin/main.py
- custom-c2: discord.com (decoded) in regwin/main.py
EXFIL
- Environment Variable Exfiltration in regwin/main.py: "os.environ['APPDATA'] ses = os.path.join(ad,'Exodus/exodus.wallet',"seed.seco") ..."
- Python File Upload to Remote in regwin/main.py: "requests.post(hook, files="
- Python Background Thread Execution in regwin/main.py: "def worker(): global buf, running while running: event = q.get() if event is Non..."
- Network Request in regwin/main.py: "requests.post("
OBFUSCATION
- Decoded Base64 Content in regwin/main.py
- Base64 Encoded Payload in regwin/main.py: ""aHR0cHM6Ly9kaXNjb3JkLmNvbS9hcGkvd2ViaG9va3MvMTQ5MzQwMjY4MzU1Njc2MTc1Mi92ZUhSRkt..."
- recovered 1 urls, 1 domains, 1 discordWebhooks from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Chai-Max Wallet Theft Indicators in regwin/main.py: "Exodus/exod"
- Shell Command Execution in regwin/main.py: "os.system("
- Chai-Max Campaign Indicators in regwin/main.py: ".wallet'"
PAYLOAD FILES
regwin/main.py
INDICATORS (IOCs)
- payloadFileHash: 9b346e69d78880114a42d29afe6e7bb6bd2de01b312ad6568f77f21edbe85411
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | svchost | all (affected) | — |
Aliases
Browse GCVE Records
805 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.