VDB
GCVE-110-OSM-2026-8436
GCVE-110-OSM-2026-8436
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution.
ENTRY
src/requests/starter.py (console-script: settings=requests.starter:main)
DESTINATION
- custom-c2: https://pepy.tech/project/requests (primary, plaintext) in PKG-INFO
- custom-c2: https://kennethreitz.org (plaintext) in PKG-INFO
- custom-c2: https://{url (plaintext) in src/requests/models.py
- custom-c2: kennethreitz.org (plaintext) in PKG-INFO
- custom-c2: static.pepy.tech (plaintext) in PKG-INFO
- custom-c2: pepy.tech (plaintext) in PKG-INFO
- urls: http://{host (c2, plaintext)
- urls: http://*example.com (c2, plaintext)
(+2 more)
EXFIL
- Network Request in PKG-INFO: "requests.get("
- Network Request in src/kryptex_os.egg-info/PKG-INFO: "requests.get("
- Network Request in src/requests/__init__.py: "requests.get("
- Network Request in src/requests/api.py: "request('GET', 'https:"
- System Information Collection in src/requests/help.py: "platform.system()"
- Network Request in src/requests/models.py: "Request('GET', 'https:"
OBFUSCATION
- Decoded Base64 Content in tests/certs/mtls/client/client.csr (x5)
- Decoded Base64 Content in tests/certs/expired/ca/ca.crt
- Decoded Base64 Content in tests/certs/expired/server/server.pem (x2)
- Decoded Base64 Content in tests/certs/mtls/client/client.pem (x2)
- Decoded Base64 Content in tests/certs/valid/server/server.pem (x2)
- recovered 2 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Shell Command Execution in src/requests/starter.py: "subprocess.run("
PAYLOAD FILES
tests/certs/mtls/client/client.csr
INDICATORS (IOCs)
- ipv6: 1::, fe80::, 1200:0000:ab00:1234:0000:2552:7777:1313
- urls: https://user:pass@proxy:8080`, https://nvd.nist.gov/vuln/detail/CVE-2023-32681, https://bugfuzz.com, http://`., http://domain.tld/path/to/resource (+39 more)
- domains: bugfuzz.com, python-requests.org, www.ietf.org, kennethreitz.com, test1.com (+10 more)
- emails: me@kennethreitz.org, me@kennethreitz.com, pass@complex.url.com, pass%20pass@complex.url.com, pass%23pass@complex.url.com (+4 more)
- payloadFileHash: 5fc31e8e331f1fdbf7f80c4840b4e70fa81f6dc46ecab811bb03134d21ab4004
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | kryptex-os | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.