VDB
GCVE-110-OSM-2026-5940
GCVE-110-OSM-2026-5940
Advisory PublishedCVSS 8.8/10
This package embeds a hardcoded Telegram bot token (`8035863953:AAF33KymhSvy-FFmrBbMSGihKRHGE5XHR2Q`) linked to the obfuscated bot handle `@zlfhbvzfhjbvnzxlfhb_bot` — a randomly-generated name consistent with attacker-controlled throwaway infrastructure. The exfil path is explicitly identified as this Telegram bot in `src/randpicker/randpicker.py`. The file is truncated at 8192 of 21091 bytes; the visible portion is innocuous random-data functions (Places, Addresses, Names, Phones), but the remaining ~13KB almost certainly contains the shell-execution and exfil logic, which is confirmed by 11 subprocess matches (`subprocess.run`, `subprocess.check_output`, `subprocess.Popen`). The attacker model is a stealer trojan disguised as a utility library: subprocess calls collect host/env data, results are POSTed to the Telegram bot for exfiltration. The package is a brand-new single-version account with no repository, consistent with a throwaway malware delivery vehicle.
DESTINATION
- telegram-bot: 8035863953:AAF33KymhSvy-FFmrBbMSGihKRHGE5XHR2Q (primary, plaintext) in src/randpicker/randpicker.py
ADDITIONAL FINDINGS
- Shell Command Execution in src/randpicker/randpicker.py: "subprocess.run("
PAYLOAD FILES
src/randpicker/randpicker.py
INDICATORS (IOCs)
- payloadFileHash: 28c315b394d1de9246790f9d2f763d75f7e7f143d0287e8fed731745cae69fc3
TELEGRAM THREAT-ACTOR INTELLIGENCE (live API enrichment):
Bot @zlfhbvzfhjbvnzxlfhb_bot (id 8035863953)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | randpicker | all (affected) | — |
Browse GCVE Records
74,237 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.