VDB

GCVE-110-OSM-2026-4159

GCVE-110-OSM-2026-4159
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 12, 2026
[osmalyze-auto] Malicious package detected. Behaviors: data exfiltration. [osmalyze-auto] Entrypoint: payloop/__init__.py (module-import: 65) Exfil: https://api.trypayloop.com (custom-c2, recovery: plaintext in payloop/_network.py) Payload: payloop/_network.py Key findings: - Environment Variable Exfiltration in payloop/_network.py: "os.environ.get("PAYLOOP_TEST_MODE") is None: try: re..." - Data Encoding for Exfiltration in payloop/_base.py: "base64.b64encode(" - Brand New Package IOCs: - urls: https://trypayloop.com/, https://developers.trypayloop.com/, https://developers.trypayloop.com, https://api.trypayloop.com, https://collector.trypayloop.com - domains: trypayloop.com, developers.trypayloop.com, api.trypayloop.com, collector.trypayloop.com - emails: noc@trypayloop.com, Response@event.response - payloadFileHash: a778d2446cfa1e404892451d863d8b21abd952a1180e244aec1e9dd9387119f5

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpayloop0.6.3 (affected), 0.6.3 (affected), 0.6.3 (affected), 0.6.3 (affected)

References

vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›