VDB
GCVE-110-OSM-2026-8171
GCVE-110-OSM-2026-8171
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
DESTINATION
- domains: cdn.nlark.com (c2, plaintext)
EXFIL
- Data Encoding for Exfiltration in encry/whats.ak: "binascii.hexlify("
- Data Encoding for Exfiltration in src/northstart_sdk/_crypto.py: "base64.b64encode("
OBFUSCATION
- Python chr() Array String Building in encry/obfuscate_final2.py: "chr(108)+chr(111)+chr(103)+chr(107)+chr(108)+chr(111)+"
- Python chr() Array String Building in encry/whats.ak: "chr(108)+chr(105)+chr(116)+chr(116)+chr(108)+"
- Decoded Base64 Content in encry/whats.ak (x7)
- Deobfuscation Failed in encry/obfuscate_final2.py
ADDITIONAL FINDINGS
- Shell Command Execution in encry/sync_arithmetic_demo.py: "subprocess.run("
- Dynamic Code Execution in src/northstart_sdk/encrypted_demo.py: "compile(source_text, f"<northstart_sdk:{demo_id}>", "exec")"
PAYLOAD FILES
encry/whats.ak
INDICATORS (IOCs)
- urls: https://gateway-sandbox.northstar.local/gateway.do, https://gateway.northstar.local/gateway.do
- sha256Hashes: 750070804f11e675c2c5782970672b42974aca70c849814e9fd2b8685a0421a7, cece542701480f7cde99f5c3b982f0c9feadb9351923c9d5512208d8bf02fa00
- payloadFileHash: 1ffce99086274a57d7c6fbfd6043f0c7dfeec501aa6b81be4261ba725740a358
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | northstart-sdk | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.