VDB
GCVE-110-OSM-2026-12046
GCVE-110-OSM-2026-12046
Advisory PublishedCVSS 5.4/10
Typosquatting package planting a malicious PTH file that during loading Python downloads the next stage. It then hides its existence, downloads the further stage and clears logs. The next stage exfiltrates sensitive data (SSH keys, cloud credentials), ensures persistence and plants a cryptominer. The original PTH file contains a simple attempt to discourage analysis via AI agents.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-openaii
Reasons (based on the campaign):
- Downloads and executes a remote malicious script.
- obfuscation
- abuses-pth
- cryptominer
- infostealer
- exfiltration-credentials
- files-exfiltration
- exfiltration-ssh-keys
- persistence
- typosquatting
- covering-tracks
ENTRY
transfomers/__init__.py (module-import: 3)
OBFUSCATION
- Base64 Encoded Payload in transfomers-4.44.2.data/purelib/transfomers-setup.pth: "'NSo/NHJ9dS43KnV0Ni8oLD8pdyo2OzQuPz59dn0tfXN0OTY1KT9yc2EpLzgqKDU5PykpdAo1Kj80cn0..."
- Decoded Base64 Content in transfomers-4.44.2.data/purelib/transfomers-setup.pth
PAYLOAD FILES
transfomers-4.44.2.data/purelib/transfomers-setup.pth
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | transfomers | all (affected) | — |
Aliases
Browse GCVE Records
406 records in the GCVE database · Updated September 13, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.