VDB
GCVE-110-OSM-2026-12864
GCVE-110-OSM-2026-12864
Advisory PublishedCVSS 8.8/10
During installation, the package executes embeded malicious executable. It then fingerprints the environment and network, looks for specific files, attempts to collect cloud credentials, and eventually attempts to exfiltrate collected information.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-auclean
Reasons (based on the campaign):
- malware
- network-scan
- files-exfiltration
- The package overrides the install command in setup.py to execute malicious code during installation.
- exfiltration-credentials
- exfiltration-cloud-tokens
- targetted-attack
ENTRY
setup.py (install-hook: install/develop/build override present)
ADDITIONAL FINDINGS
- Shell Command Execution in auclean/_io.py: "subprocess.run("
PAYLOAD FILES
auclean/_io.py (+ setup.py)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | auclean | all (affected) | — |
Aliases
Browse GCVE Records
3,164 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.