VDB
GCVE-110-OSM-2026-12696
GCVE-110-OSM-2026-12696
Advisory PublishedCVSS 8.8/10
This package implements a CI/CD supply-chain poisoning attack. The setup.py, executing at install time, steals a GitHub token either from the GITHUB_TOKEN environment variable or by parsing a base64-encoded AUTHORIZATION header from the workspace .git/config file. It then uses that token to clone the victim's repository, create a branch named 'feature/ci-health-check', and inject a GitHub Actions workflow file at .github/workflows/ci-health-check.yml — granting the attacker persistent code execution in the victim's CI pipeline with access to all repository secrets. The attacker implemented two delivery paths (git push bypassing the API restriction on .github/workflows, with a REST API fallback using base64-encoded content PUT), demonstrating deliberate, sophisticated tradecraft. The brand-new single-version package with no repository, published under a vague name, is consistent with a throwaway malicious package designed for one-shot targeting of organizations running pip installs inside GitHub Actions.
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Python File Upload to Remote in setup.py: "urllib.request.Request( url, data="
- Data Encoding for Exfiltration in setup.py: "base64.b64encode("
- Network Request in setup.py: "urllib.request.Request("
ADDITIONAL FINDINGS
- Shell Command Execution in setup.py: "subprocess.run("
- Brand New Package
PAYLOAD FILES
setup.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | bfox-build-utils | all (affected) | — |
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.