VDB

GCVE-110-OSM-2026-12043

GCVE-110-OSM-2026-12043
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 11, 2026
Typosquatting package planting a malicious PTH file that during loading Python downloads the next stage. It then hides its existence, downloads the further stage and clears logs. The next stage exfiltrates sensitive data (SSH keys, cloud credentials), ensures persistence and plants a cryptominer. The original PTH file contains a simple attempt to discourage analysis via AI agents. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-openaii ENTRY openaii/__init__.py (module-import: 3) OBFUSCATION - Base64 Encoded Payload in openaii-1.55.3.data/purelib/openaii-setup.pth: "'NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuPz59dn0tfXN0OTY1KT9yc2EpLzgqKDU5PykpdAo1Kj80cn0..." - Decoded Base64 Content in openaii-1.55.3.data/purelib/openaii-setup.pth PAYLOAD FILES openaii-1.55.3.data/purelib/openaii-setup.pth

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownopenaiiall (affected)

References

advisory
vendor

Browse GCVE Records

406 records in the GCVE database · Updated September 13, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›