VDB
GCVE-110-OSM-2026-12851
GCVE-110-OSM-2026-12851
Advisory PublishedCVSS 9.6/10
This package implements a full-featured C2 RAT (Remote Access Trojan) disguised as a text beautification utility. The setup.py installs a cmdclass hook that imports beautifyText._compat on installation, which decodes a base64-encoded C2 URL, registers the victim machine with device metadata (hostname, OS, username, CWD, Python version), and enters a persistent beacon loop polling for jobs. The agent supports arbitrary shell command execution (_run_cmd with shell=True), file exfiltration (_read_file returning base64-encoded file contents), and file upload (_write_file) — a complete read/write/exec RAT toolkit. It spawns a detached background process (using DETACHED_PROCESS flags on Windows, start_new_session on Linux) with suppressed stdout/stderr to persist silently after install.
ENTRY
setup.py (install-hook: install/develop/build override present)
- setup.py Code Execution in setup.py
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Python File Upload to Remote in beautifyText/_compat.py: "urllib.request.Request( _HOST + path, data="
- System Information Exfiltration in beautifyText/_compat.py: "os.getcwd(), } _UA = ( "Mozilla/5.0 (Linux; Android 15) AppleWebKit/537.36 " "(K..."
- Data Encoding for Exfiltration in beautifyText/_compat.py: "base64.b64encode("
- Network Request in beautifyText/_compat.py: "urllib.request.Request("
- System Information Collection in beautifyText/_compat.py: "socket.gethostname()"
OBFUSCATION
- Decoded Base64 Content in beautifyText/_compat.py
- recovered 1 urls from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Shell Command Execution in beautifyText/_compat.py: "subprocess.run("
- Silent Process Execution in beautifyText/_compat.py: "stdout=subprocess.DEVNULL"
- Setup.py Command Override in setup.py: "cmdclass={"install": _InstallHook, "develop""
PAYLOAD FILES
beautifyText/_compat.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | beautifytext | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.