VDB
GCVE-110-OSM-2026-11631
GCVE-110-OSM-2026-11631
Advisory PublishedCVSS 9.6/10
The provided functionality hides code that exfiltrates files to a remote location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-asti
Reasons (based on the campaign):
- files-exfiltration
- action-hidden-in-lib-usage
- target:android
Judge assessment: This looks like an attacker-controlled Python payload intended to hide and execute a loader consistent with an infostealer campaign, not a normal library. The `invisible-ferret` and `invisible-ferret-lambda-exec` detections in `qoeoe/starts.py`, plus the unwrapped `decoded-python-lambda-exec` finding, show 5-layer obfuscation leading to executable code. The decoded indicators include a Telegram bot token (`1263262891:neVZzZ8aKyH25k8BADzDkkurSehW3NuWgrg`) and suspicious network targets such as `tapi.bale.ai`, which strongly support exfiltration behavior. The OSV advisory’s claim of hidden file exfiltration is corroborated by the actual obfuscated entry file and recovered exfil IOC, so I would treat this as malicious from a malware operator model using a covert loader to steal data.
DESTINATION
- 1 exfil (telegram-bot)
(values recorded in verified_iocs)
OBFUSCATION
- Python Lambda Exec Obfuscation Unwrapped in qoeoe/starts.py
- recovered 6 ipv4, 2 ipv6, 4 urls, 3 domains, 1 telegramBots from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Invisible Ferret Obfuscation in qoeoe/starts.py: "exec((_)(b'"
- Invisible Ferret Lambda Exec Pattern in qoeoe/starts.py: "exec((_)("
PAYLOAD FILES
qoeoe/starts.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | qoeoe | all (affected) | — |
Aliases
Browse GCVE Records
3,521 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.