VDB
GCVE-110-OSM-2026-8172
GCVE-110-OSM-2026-8172
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, network activity.
ENTRY
setup.py (install-hook: install/develop/build override present)
DESTINATION
- custom-c2: 203.0.113.10 (primary, plaintext) in internal/netmon/netmon_test.go
EXFIL
- Corporate Environment Targeting in internal/netmon/netmon_test.go: "tmon import ( "context" "errors" "net" "strings" "sync" "testing" "time" ) func ..."
- Corporate Environment Targeting in proxy_checker_j.egg-info/SOURCES.txt: "tmon/netmon.go internal/netmon/netmon_test"
- Suspicious Domain in internal/netmon/netmon.go: "https://1.1.1.1"
ADDITIONAL FINDINGS
- Shell Command Execution in setup.py: "subprocess.run("
PAYLOAD FILES
internal/netmon/netmon_test.go (+ proxy_checker_j.egg-info/SOURCES.txt)
INDICATORS (IOCs)
- ipv4: 1.1.1.1, 1.0.0.1, 9.9.9.9, 149.112.112.112
- ipv6: 2606:4700:4700::
- urls: https://1.1.1.1/dns-query, https://1.0.0.1/dns-query, https://9.9.9.9/dns-query, https://149.112.112.112/dns-query, https://1.1.1.1
- domains: dns.quad9.net
- payloadFileHash: ddc895220e0a4c75ca59c31ded44be7708b862cdc346e8e6f3566a73db0fef24
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | proxy-checker-j | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.