VDB

GCVE-110-OSM-2026-10636

GCVE-110-OSM-2026-10636
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 17, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code. DESTINATION - discord-webhook: discord.com/api/webhooks/1493402683556761752/veHRFKpZ1UGm13xuS2NdBKgn7QPaKRH-OcQerHufSzCBYZrrOK9uGqyHUODSJULbrWj9 (primary, decoded) in regwin/main.py - custom-c2: https://discord.com/api/webhooks/1493402683556761752/veHRFKpZ1UGm13xuS2NdBKgn7QPaKRH-OcQerHufSzCBYZrrOK9uGqyHUODSJULbrWj9 (decoded) in regwin/main.py - custom-c2: discord.com (decoded) in regwin/main.py EXFIL - Environment Variable Exfiltration in regwin/main.py: "os.environ['APPDATA'] ses = os.path.join(ad,'Exodus/exodus.wallet',"seed.seco") ..." - Python File Upload to Remote in regwin/main.py: "requests.post(hook, files=" - Python Background Thread Execution in regwin/main.py: "def worker(): global buf, running while running: event = q.get() if event is Non..." - Network Request in regwin/main.py: "requests.post(" OBFUSCATION - Decoded Base64 Content in regwin/main.py - Base64 Encoded Payload in regwin/main.py: ""aHR0cHM6Ly9kaXNjb3JkLmNvbS9hcGkvd2ViaG9va3MvMTQ5MzQwMjY4MzU1Njc2MTc1Mi92ZUhSRkt..." - recovered 1 urls, 1 domains, 1 discordWebhooks from decoded/deobfuscated content ADDITIONAL FINDINGS - Chai-Max Wallet Theft Indicators in regwin/main.py: "Exodus/exod" - Shell Command Execution in regwin/main.py: "os.system(" - Chai-Max Campaign Indicators in regwin/main.py: ".wallet'" PAYLOAD FILES regwin/main.py INDICATORS (IOCs) - payloadFileHash: 9b346e69d78880114a42d29afe6e7bb6bd2de01b312ad6568f77f21edbe85411

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsvchostall (affected)

References

advisory
vendor

Browse GCVE Records

805 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›