VDB

GCVE-110-OSM-2026-12864

GCVE-110-OSM-2026-12864
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 22, 2026
During installation, the package executes embeded malicious executable. It then fingerprints the environment and network, looks for specific files, attempts to collect cloud credentials, and eventually attempts to exfiltrate collected information. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-auclean Reasons (based on the campaign): - malware - network-scan - files-exfiltration - The package overrides the install command in setup.py to execute malicious code during installation. - exfiltration-credentials - exfiltration-cloud-tokens - targetted-attack ENTRY setup.py (install-hook: install/develop/build override present) ADDITIONAL FINDINGS - Shell Command Execution in auclean/_io.py: "subprocess.run(" PAYLOAD FILES auclean/_io.py (+ setup.py)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownaucleanall (affected)—

References

advisory
vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›