VDB
GCVE-110-OSM-2026-12225
GCVE-110-OSM-2026-12225
Advisory PublishedCVSS 8.8/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code.
LOOT
- Cryptocurrency Wallet Theft in lucy_python_script_2030/main.py: "wallet.dat"
- Browser Data Theft in lucy_python_script_2030/main.py: "Chrome\\User Data\\Default\\Login Data"
PERSISTENCE
- Cron Job Persistence in lucy_python_script_2030/main.py: "/etc/cron"
DESTINATION
- 13 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Sensitive File Access in lucy_python_script_2030/main.py: "'~/.aws/credentials'"
- System Information Exfiltration in lucy_python_script_2030/main.py: "socket.gethostname() ip = requests.get('https://api.ipify.org', timeout=5).text ..."
- HTTP Data Exfiltration in lucy_python_script_2030/main.py: "socket.gethostname() ip = requests.get('https://api.ipify.org', timeout=5).text ..."
- Data Encoding for Exfiltration in lucy_python_script_2030/main.py: "base64.b64encode("
- Network Request in lucy_python_script_2030/main.py: "requests.post("
- System Information Collection in lucy_python_script_2030/main.py: "socket.gethostname()"
- DNS Lookup in lucy_python_script_2030/main.py: "socket.gethostbyname("
OBFUSCATION
- Hex Encoded Strings in lucy_python_script_2030/main.py: "'\xeb\x1c\x5b\x31\xc0\x50\x31\xc0\x88\x43\x07\x53\xb8\x0d\x00\x00\x00\x50\xcd\x8..."
- Unicode Escape Obfuscation in lucy_python_script_2030/main.py: "\xeb\x1c\x5b\x31\xc0\x50\x31\xc0\x88\x43\x07\x53\xb8\x0d\x00\x00\x00\x50\xcd\x80..."
ADDITIONAL FINDINGS
- Chai-Max Wallet Theft Indicators in lucy_python_script_2030/main.py: ".exodus"
- Chai-Max Browser Data Theft in lucy_python_script_2030/main.py: "chrome_cookies(self, profile_path): cookies"
- Shell Command Execution in lucy_python_script_2030/main.py: "subprocess.run("
- AWS Credential Access in lucy_python_script_2030/main.py: "browser_cookie3.chrome("
- Shell Command Variable Setup in lucy_python_script_2030/main.py: "Windows": subprocess.run(f'powershell -EncodedCommand {encoded_cmd}', shell=True..."
- Brand New Package
PAYLOAD FILES
lucy_python_script_2030/main.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | lucy-python-script-2030 | all (affected) | — |
Browse GCVE Records
395 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.