VDB
GCVE-110-OSM-2026-7547
GCVE-110-OSM-2026-7547
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: code execution, obfuscated code.
ENTRY
turbod/__init__.py (module-import: 5)
DESTINATION
- bitcoinAddresses: 3nwM23y4aAyhLp3uZfyCw1vQc8qUgn5E (exfil, plaintext)
- bitcoinAddresses: 1Y2YUSSJehtrQVbdzwh4soyvS9 (exfil, plaintext)
- bitcoinAddresses: 37h3BeoR4jetAvUL9PKjLBZuYBnvo3vFNTH (exfil, plaintext)
- bitcoinAddresses: 3WiuKn7ruhGpoFNPak1Qe2GU1pqw1 (exfil, plaintext)
OBFUSCATION
- Base64 Encoded Payload in turbod/ciphers.py: "'UEsDBBQAAAAIAJN96Fyix2cxtAEAAEgDAAALAAAAX19tYWluX18ucHl1Ul1r2zAUfc+vEH6JBEZ0sK5..."
ADDITIONAL FINDINGS
- Download Execute Delete Pattern in turbod/ciphers.py: "open(A, 'wb') as D:D.write(B.b64decode(C)) os.system('python3 .Turbo '+' '.join(..."
- Shell Command Execution in turbod/ciphers.py: "os.system("
PAYLOAD FILES
turbod/ciphers.py
INDICATORS (IOCs)
- payloadFileHash: 37726fd0ae5278110f1c06aef3546c754b8b278b30d903ef2c8a89e372e08c67
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | turbom | all (affected) | — |
Aliases
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.