VDB
GCVE-110-OSM-2026-8413
GCVE-110-OSM-2026-8413
Advisory PublishedCVSS 5.4/10
Suspicious package detected. Behaviors: data exfiltration.
DESTINATION
- custom-c2: https://api.counterapi.dev/v2/swampon/swampo/up (primary, plaintext) in swampo/analytics.py
- custom-c2: api.counterapi.dev (plaintext) in swampo/analytics.py
EXFIL
- Network Request in swampo/analytics.py: "Request( "https:"
PAYLOAD FILES
swampo/analytics.py
INDICATORS (IOCs)
- urls: https://youtu.be/43c-Sm5GMbc, https://example.com`, https://frida.re/docs/, https://source.android.com/security/bulletin, https://portswigger.net/burp (+7 more)
- domains: egghead.io, Guitar.pro, sgcarstrends.com, api.staging.sgcarstrends.com, staging.sgcarstrends.com (+10 more)
- emails: hello@swampo.dev
- payloadFileHash: 431f974efd7ab1c2c02a7eced3e4d67ac20bc4b4b1f052316723768c84bf1ffd
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | swampo | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.