VDB

GCVE-110-OSM-2026-8171

GCVE-110-OSM-2026-8171
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. DESTINATION - domains: cdn.nlark.com (c2, plaintext) EXFIL - Data Encoding for Exfiltration in encry/whats.ak: "binascii.hexlify(" - Data Encoding for Exfiltration in src/northstart_sdk/_crypto.py: "base64.b64encode(" OBFUSCATION - Python chr() Array String Building in encry/obfuscate_final2.py: "chr(108)+chr(111)+chr(103)+chr(107)+chr(108)+chr(111)+" - Python chr() Array String Building in encry/whats.ak: "chr(108)+chr(105)+chr(116)+chr(116)+chr(108)+" - Decoded Base64 Content in encry/whats.ak (x7) - Deobfuscation Failed in encry/obfuscate_final2.py ADDITIONAL FINDINGS - Shell Command Execution in encry/sync_arithmetic_demo.py: "subprocess.run(" - Dynamic Code Execution in src/northstart_sdk/encrypted_demo.py: "compile(source_text, f"<northstart_sdk:{demo_id}>", "exec")" PAYLOAD FILES encry/whats.ak INDICATORS (IOCs) - urls: https://gateway-sandbox.northstar.local/gateway.do, https://gateway.northstar.local/gateway.do - sha256Hashes: 750070804f11e675c2c5782970672b42974aca70c849814e9fd2b8685a0421a7, cece542701480f7cde99f5c3b982f0c9feadb9351923c9d5512208d8bf02fa00 - payloadFileHash: 1ffce99086274a57d7c6fbfd6043f0c7dfeec501aa6b81be4261ba725740a358

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownnorthstart-sdkall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›