VDB

GCVE-110-OSM-2026-11631

GCVE-110-OSM-2026-11631
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 4, 2026
The provided functionality hides code that exfiltrates files to a remote location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-asti Reasons (based on the campaign): - files-exfiltration - action-hidden-in-lib-usage - target:android Judge assessment: This looks like an attacker-controlled Python payload intended to hide and execute a loader consistent with an infostealer campaign, not a normal library. The `invisible-ferret` and `invisible-ferret-lambda-exec` detections in `qoeoe/starts.py`, plus the unwrapped `decoded-python-lambda-exec` finding, show 5-layer obfuscation leading to executable code. The decoded indicators include a Telegram bot token (`1263262891:neVZzZ8aKyH25k8BADzDkkurSehW3NuWgrg`) and suspicious network targets such as `tapi.bale.ai`, which strongly support exfiltration behavior. The OSV advisory’s claim of hidden file exfiltration is corroborated by the actual obfuscated entry file and recovered exfil IOC, so I would treat this as malicious from a malware operator model using a covert loader to steal data. DESTINATION - 1 exfil (telegram-bot) (values recorded in verified_iocs) OBFUSCATION - Python Lambda Exec Obfuscation Unwrapped in qoeoe/starts.py - recovered 6 ipv4, 2 ipv6, 4 urls, 3 domains, 1 telegramBots from decoded/deobfuscated content ADDITIONAL FINDINGS - Invisible Ferret Obfuscation in qoeoe/starts.py: "exec((_)(b'" - Invisible Ferret Lambda Exec Pattern in qoeoe/starts.py: "exec((_)(" PAYLOAD FILES qoeoe/starts.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownqoeoeall (affected)

References

advisory
vendor

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›