VDB
GCVE-110-OSM-2026-12479
GCVE-110-OSM-2026-12479
Advisory PublishedCVSS 9.6/10
During import, the obfuscated code downloads and executes an executable. The remote executable did not exist during analysis, but the repository used to host it overlaps with previous campaign 2026-07-yt-api-dlp
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-pymem-win
Reasons (based on the campaign):
- obfuscation
- Downloads and executes a remote executable.
- clones-real-package
ENTRY
pymem/__init__.py (module-import: 1139)
OBFUSCATION
- Python Lambda Exec Obfuscation Unwrapped in pymem/__init__.py
ADDITIONAL FINDINGS
- Invisible Ferret Obfuscation in pymem/__init__.py: "zlib').decompress(__import__('base64').b64decode(__[::-1]))"
- Invisible Ferret Lambda Exec Pattern in pymem/__init__.py: "exec((_)("
- Shell Command Execution in PKG-INFO: "subprocess.Popen("
PAYLOAD FILES
pymem/__init__.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | pymem-win | all (affected) | — |
Aliases
Browse GCVE Records
400 records in the GCVE database · Updated September 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.