VDB
GCVE-110-OSM-2026-4159
GCVE-110-OSM-2026-4159
Advisory PublishedCVSS 9.6/10
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration.
[osmalyze-auto] Entrypoint: payloop/__init__.py (module-import: 65)
Exfil: https://api.trypayloop.com (custom-c2, recovery: plaintext in payloop/_network.py)
Payload: payloop/_network.py
Key findings:
- Environment Variable Exfiltration in payloop/_network.py: "os.environ.get("PAYLOOP_TEST_MODE") is None:
try:
re..."
- Data Encoding for Exfiltration in payloop/_base.py: "base64.b64encode("
- Brand New Package
IOCs:
- urls: https://trypayloop.com/, https://developers.trypayloop.com/, https://developers.trypayloop.com, https://api.trypayloop.com, https://collector.trypayloop.com
- domains: trypayloop.com, developers.trypayloop.com, api.trypayloop.com, collector.trypayloop.com
- emails: noc@trypayloop.com, Response@event.response
- payloadFileHash: a778d2446cfa1e404892451d863d8b21abd952a1180e244aec1e9dd9387119f5
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | payloop | 0.6.3 (affected), 0.6.3 (affected), 0.6.3 (affected), 0.6.3 (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.