VDB

GCVE-110-OSM-2026-12851

GCVE-110-OSM-2026-12851
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 30, 2026
This package implements a full-featured C2 RAT (Remote Access Trojan) disguised as a text beautification utility. The setup.py installs a cmdclass hook that imports beautifyText._compat on installation, which decodes a base64-encoded C2 URL, registers the victim machine with device metadata (hostname, OS, username, CWD, Python version), and enters a persistent beacon loop polling for jobs. The agent supports arbitrary shell command execution (_run_cmd with shell=True), file exfiltration (_read_file returning base64-encoded file contents), and file upload (_write_file) — a complete read/write/exec RAT toolkit. It spawns a detached background process (using DETACHED_PROCESS flags on Windows, start_new_session on Linux) with suppressed stdout/stderr to persist silently after install. ENTRY setup.py (install-hook: install/develop/build override present) - setup.py Code Execution in setup.py DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Python File Upload to Remote in beautifyText/_compat.py: "urllib.request.Request( _HOST + path, data=" - System Information Exfiltration in beautifyText/_compat.py: "os.getcwd(), } _UA = ( "Mozilla/5.0 (Linux; Android 15) AppleWebKit/537.36 " "(K..." - Data Encoding for Exfiltration in beautifyText/_compat.py: "base64.b64encode(" - Network Request in beautifyText/_compat.py: "urllib.request.Request(" - System Information Collection in beautifyText/_compat.py: "socket.gethostname()" OBFUSCATION - Decoded Base64 Content in beautifyText/_compat.py - recovered 1 urls from decoded/deobfuscated content ADDITIONAL FINDINGS - Shell Command Execution in beautifyText/_compat.py: "subprocess.run(" - Silent Process Execution in beautifyText/_compat.py: "stdout=subprocess.DEVNULL" - Setup.py Command Override in setup.py: "cmdclass={"install": _InstallHook, "develop"" PAYLOAD FILES beautifyText/_compat.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownbeautifytextall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›