VDB
GCVE-110-OSM-2026-8428
GCVE-110-OSM-2026-8428
Advisory PublishedCVSS 5.4/10
Suspicious package detected. Behaviors: data exfiltration, code execution.
ENTRY
requests/__init__.py (module-import: 111)
DESTINATION
- custom-c2: https://{url (primary, plaintext) in requests/models.py
- custom-c2: https://pepy.tech/project/requests (plaintext) in requests_testik11-2.33.0.dist-info/METADATA
- custom-c2: https://kennethreitz.org (plaintext) in requests_testik11-2.33.0.dist-info/METADATA
- custom-c2: static.pepy.tech (plaintext) in requests_testik11-2.33.0.dist-info/METADATA
- custom-c2: pepy.tech (plaintext) in requests_testik11-2.33.0.dist-info/METADATA
EXFIL
- Network Request in requests/__init__.py: "requests.get("
- Network Request in requests/api.py: "request('GET', 'https:"
- System Information Collection in requests/help.py: "platform.system()"
- Network Request in requests/models.py: "Request('GET', 'https:"
- Network Request in requests_testik11-2.33.0.dist-info/METADATA: "requests.get("
PAYLOAD FILES
requests/help.py (+ requests/__init__.py, requests/api.py)
INDICATORS (IOCs)
- ipv6: 1::
- urls: http://domain.tld/path/to/resource, http://host.name, https://www.ietf.org/rfc/rfc4627.txt
- domains: kennethreitz.org, www.ietf.org
- emails: me@kennethreitz.org
- payloadFileHash: bccadffb7379b8e92c9c5a2a4cb1f36c66f7570dbb5b085d85d04984fe652fed
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | requests-testik11 | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.