VDB
GCVE-110-OSM-2026-2751
GCVE-110-OSM-2026-2751
Advisory PublishedCVSS 8.8/10
Malicious package detected.
Payload: pypi/jqmc@0.1.0/jqmc/obsolete/lrdmc_serial.py
Secondary files: pypi/jqmc@0.1.0/jqmc/obsolete/vmc_serial.py, pypi/jqmc@0.1.0/.devcontainer/Dockerfile
Key findings:
- Startup Persistence in pypi/jqmc@0.1.0/.devcontainer/Dockerfile: ".bashrc"
- Dangerous Function Calls in pypi/jqmc@0.1.0/jqmc/determinant.py: "pickle.load("
- Dangerous Function Calls in pypi/jqmc@0.1.0/jqmc/jqmc_cli.py: "pickle.load("
- Dangerous Function Calls in pypi/jqmc@0.1.0/jqmc/jqmc_tool.py: "pickle.loads("
- Startup Persistence in pypi/jqmc@0.1.0/jqmc/obsolete/lrdmc_serial.py: ".profile"
IOCs:
- urls: https://pre-commit.com, https://pre-commit.com/hooks.html, https://kousuke-nakano.github.io/jQMC/, https://fhi-aims.org/, https://www.diracprogram.org (+37 more)
- domains: python-poetry.org, pdm.fming.dev, pre-commit.com, kousuke-nakano.github.io, fhi-aims.org (+20 more)
- payloadFileHash: 8b04a8b3a0a5f97352cd1cfe7ec77b9b098799680db467a93a03e2ec6dae02a3
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | jqmc | * (affected) | — |
Browse GCVE Records
74,299 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.