VDB
GCVE-110-OSM-2026-10642
GCVE-110-OSM-2026-10642
Advisory PublishedCVSS 8.8/10
Malicious package detected. Behaviors: data exfiltration, network activity.
DESTINATION
- custom-c2: http://user:pass@host/.. (primary, plaintext) in pypi/immaster-sdk@0.1.0/immaster/vision.py
- urls: https://ollama.com (c2, plaintext)
- urls: http://user:pass@ (c2, plaintext)
- urls: https://ollama.com/install.sh (c2, plaintext)
- domains: ollama.com (c2, plaintext)
EXFIL
- Curl/Wget Pipe to Shell in pypi/immaster-sdk@0.1.0/PKG-INFO: "curl -fsSL https://ollama.com/install.sh | sh"
- Python File Upload to Remote in pypi/immaster-sdk@0.1.0/immaster/llm.py: "urllib.request.Request( f"{self.host}/api/chat", data="
- Data Encoding for Exfiltration in pypi/immaster-sdk@0.1.0/immaster/llm.py: "json.dumps({ "model": self.model, "messages": messages, "stream": False, "keep_a..."
- Data Encoding for Exfiltration in pypi/immaster-sdk@0.1.0/immaster/vision.py: "base64.b64encode("
- Data Encoding for Exfiltration in pypi/immaster-sdk@0.1.0/immaster/voice.py: "json.dumps({"text": txt or ""}).encode"
- Network Request in pypi/immaster-sdk@0.1.0/immaster/llm.py: "urllib.request.Request("
- Network Request in pypi/immaster-sdk@0.1.0/immaster/vision.py: "urllib.request.Request("
PAYLOAD FILES
pypi/immaster-sdk@0.1.0/immaster/llm.py (+ pypi/immaster-sdk@0.1.0/immaster/vision.py)
INDICATORS (IOCs)
- urls: http://localhost:11434`, http://localhost:8000`, http://host:1234/v1
- payloadFileHash: 75b6df2865b7047e5e3d3781edaed7cef2cac13e2ebc440a06be61d4a996822f
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | immaster-sdk | all (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.