VDB

GCVE-110-OSM-2026-8172

GCVE-110-OSM-2026-8172
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 15, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, network activity. ENTRY setup.py (install-hook: install/develop/build override present) DESTINATION - custom-c2: 203.0.113.10 (primary, plaintext) in internal/netmon/netmon_test.go EXFIL - Corporate Environment Targeting in internal/netmon/netmon_test.go: "tmon import ( "context" "errors" "net" "strings" "sync" "testing" "time" ) func ..." - Corporate Environment Targeting in proxy_checker_j.egg-info/SOURCES.txt: "tmon/netmon.go internal/netmon/netmon_test" - Suspicious Domain in internal/netmon/netmon.go: "https://1.1.1.1" ADDITIONAL FINDINGS - Shell Command Execution in setup.py: "subprocess.run(" PAYLOAD FILES internal/netmon/netmon_test.go (+ proxy_checker_j.egg-info/SOURCES.txt) INDICATORS (IOCs) - ipv4: 1.1.1.1, 1.0.0.1, 9.9.9.9, 149.112.112.112 - ipv6: 2606:4700:4700:: - urls: https://1.1.1.1/dns-query, https://1.0.0.1/dns-query, https://9.9.9.9/dns-query, https://149.112.112.112/dns-query, https://1.1.1.1 - domains: dns.quad9.net - payloadFileHash: ddc895220e0a4c75ca59c31ded44be7708b862cdc346e8e6f3566a73db0fef24

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownproxy-checker-jall (affected)

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›