VDB

GCVE-110-OSM-2026-12068

GCVE-110-OSM-2026-12068
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 13, 2026
The investigating researcher identifies this repository as a resource sourced by a malicious PyPI package to compromise developer machines. It supplies reconnaissance tooling capable of exposing local credentials, host configuration, and privilege-escalation opportunities. The malicious delivery association is researcher-reported; the package identity and loader have been requested for independent verification. This classification does not assert that upstream LinPEAS is malware or that the hosted script contains an added backdoor. Analyzed artifact: linpeas.sh The script enumerates systems, users, processes, services, permissions, network configuration, readable credentials, and cloud metadata, and prints findings. On non-macOS systems with Bash it decodes and invokes embedded Linux Exploit Suggester. Independent static decoding found its exploit-download options disabled in the parent invocation. Conditional paths include password guessing, local privileged-binary execution under strace, container mount/write probes, network scanning, and user-configured port forwarding. Temporary artifacts include /tmp/cgroup_3628d4, .ips.tmp, .ips, and a mktemp process-list file. A hostname-reporting function matches historical upstream code and is not classified as malicious C2. No intentional persistence or blockchain C2 was identified. The researcher reports malicious PyPI delivery; exact package/version, loader, execution trigger, and downstream exfiltration remain pending evidence. No sample code was executed. No discovered endpoint was contacted. The full artifact was not matched byte-for-byte to an official release.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownGit commit 3dea4cfb0e278ca9ffa605854b5187d89a3ba18f (affected)

Browse GCVE Records

406 records in the GCVE database · Updated September 13, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›