VDB
GCVE-110-OSM-2026-8352
GCVE-110-OSM-2026-8352
Advisory PublishedCVSS 8.8/10
Malicious code in cpu-optimizers2-33 (PyPI)
Details:
---
_-= Per source details. Do not edit below this line.=-_
## Source: kam193 (eb2ab5bcc8a1a35fbd4e5d9b19ac517134ea3fd497e66d7d7126089743804a1c)
Clones of legitimate libraries with malicious modifications intended to download malicious remote code. The remote script allows executing arbitrary files through a Telegram as C2 channel. The package installs a generic entry point triggering malicious action.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-pipipipi
Reasons (based on the campaign):
- clones-real-package
- rat
- Downloads and executes a remote malicious script.
- typosquatting
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | cpu-optimizers2-33 | all (affected) | — |
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.