VDB
GCVE-110-OSM-2026-13375
GCVE-110-OSM-2026-13375
Advisory PublishedCVSS 5.4/10
During installation or import, the package exfiltrates basic information in a dependency confusion attempt. The user identifies themselves as a HackerOne user abusing the PyPI for the purpose of a bug bounty program.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-hackerone-bugbounty
Reasons (based on the campaign):
- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
- dependency-confusion
Judge assessment: This package is a self-declared dependency confusion proof-of-concept for a HackerOne bug bounty program targeting Epic Games, as explicitly stated in the entrypoint comments ('SECURITY RESEARCH CANARY - fallback path (Epic Games HackerOne dep-confusion PoC)'). The code in lore_cs/__init__.py and setup.py does perform real exfiltration: hostname, install path, cwd are POSTed to a hardcoded IP (185.158.107.175:8787) on both install and import. The OSV advisory MAL-2026-17639 corroborates this as a pentest/bug-bounty artifact (PROBABLY_PENTEST, GENERIC-hackerone-bugbounty campaign), and the author email 0xwise@wearehackerone.com aligns with that attribution. While the intent appears to be security research rather than malicious attack, the package still performs live network exfiltration of system metadata against any victim who installs it, making it unsuitable for general distribution — it warrants flagging rather than silent suppression.
ENTRY
lore_cs/__init__.py (module-import: 21)
DESTINATION
- 2 c2 (ipv4, urls)
(values recorded in verified_iocs)
EXFIL
- System Information Exfiltration in lore_cs/__init__.py: "socket.gethostname(), "installPath": os.path.dirname(os.path.abspath(__file__)),..."
- HTTP Data Exfiltration in lore_cs/__init__.py: "os.getcwd(), "userAgent": "python/import", "protocol": "http", } _data = json.du..."
- Data Encoding for Exfiltration in lore_cs/__init__.py: "json.dumps(_payload).encode"
- Python File Upload to Remote in setup.py: "urllib.request.Request( url, data="
- System Information Exfiltration in setup.py: "socket.gethostname(), "installPath": _HERE, "cwd": os.getcwd(), "userAgent": "pi..."
- Data Encoding for Exfiltration in setup.py: "json.dumps(payload).encode"
- Suspicious Domain in PKG-INFO: "http://185.158.107.175"
- Network Request in lore_cs/__init__.py: "urllib.request.Request("
(+6 more)
PAYLOAD FILES
lore_cs/__init__.py (+ setup.py)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | lore-cs | all (affected) | — |
Aliases
Browse GCVE Records
3,310 records in the GCVE database · Updated October 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.