VDB
GCVE-110-OSM-2026-4134
GCVE-110-OSM-2026-4134
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: code execution, obfuscated code.
[osmalyze-auto] Entrypoint: setup.py (install-hook: install/develop/build override present)
Payload: setup.py
Key findings:
- Python Exec with Encoded Content in setup.py: "exec(binascii"
- Decoded Hex String Content in setup.py
- Shell Command Execution in setup.py: "subprocess.Popen("
- Python Binascii String Hiding in setup.py: "binascii.unhexlify('"
- setup.py Code Execution in setup.py: "class PostInstall(install):
def run(self):
install.run(self)
..."
IOCs:
- urls: http://144.126.142.148:5555/tao
- ips: 144.126.142.148
- paths: ~/.bittensor/wallets/
- payloadFileHash: d3c17984b7790d73b2d7f376242250e4d8737db9f9dde5e287751ce7d922f676
Decoded/deobfuscated IOCs:
- urls: http://144.126.142.148:5555/tao
- ips: 144.126.142.148
- paths: ~/.bittensor/wallets/
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ninja-core-optimizer | all (affected) | — |
Aliases
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.