VDB

GCVE-110-OSM-2026-12225

GCVE-110-OSM-2026-12225
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 10, 2026
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, obfuscated code. LOOT - Cryptocurrency Wallet Theft in lucy_python_script_2030/main.py: "wallet.dat" - Browser Data Theft in lucy_python_script_2030/main.py: "Chrome\\User Data\\Default\\Login Data" PERSISTENCE - Cron Job Persistence in lucy_python_script_2030/main.py: "/etc/cron" DESTINATION - 13 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Sensitive File Access in lucy_python_script_2030/main.py: "'~/.aws/credentials'" - System Information Exfiltration in lucy_python_script_2030/main.py: "socket.gethostname() ip = requests.get('https://api.ipify.org', timeout=5).text ..." - HTTP Data Exfiltration in lucy_python_script_2030/main.py: "socket.gethostname() ip = requests.get('https://api.ipify.org', timeout=5).text ..." - Data Encoding for Exfiltration in lucy_python_script_2030/main.py: "base64.b64encode(" - Network Request in lucy_python_script_2030/main.py: "requests.post(" - System Information Collection in lucy_python_script_2030/main.py: "socket.gethostname()" - DNS Lookup in lucy_python_script_2030/main.py: "socket.gethostbyname(" OBFUSCATION - Hex Encoded Strings in lucy_python_script_2030/main.py: "'\xeb\x1c\x5b\x31\xc0\x50\x31\xc0\x88\x43\x07\x53\xb8\x0d\x00\x00\x00\x50\xcd\x8..." - Unicode Escape Obfuscation in lucy_python_script_2030/main.py: "\xeb\x1c\x5b\x31\xc0\x50\x31\xc0\x88\x43\x07\x53\xb8\x0d\x00\x00\x00\x50\xcd\x80..." ADDITIONAL FINDINGS - Chai-Max Wallet Theft Indicators in lucy_python_script_2030/main.py: ".exodus" - Chai-Max Browser Data Theft in lucy_python_script_2030/main.py: "chrome_cookies(self, profile_path): cookies" - Shell Command Execution in lucy_python_script_2030/main.py: "subprocess.run(" - AWS Credential Access in lucy_python_script_2030/main.py: "browser_cookie3.chrome(" - Shell Command Variable Setup in lucy_python_script_2030/main.py: "Windows": subprocess.run(f'powershell -EncodedCommand {encoded_cmd}', shell=True..." - Brand New Package PAYLOAD FILES lucy_python_script_2030/main.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownlucy-python-script-2030all (affected)

Browse GCVE Records

395 records in the GCVE database · Updated September 17, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›