VDB

GCVE-110-OSM-2026-8490

GCVE-110-OSM-2026-8490
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 27, 2026
Dependency-confusion/typosquat crate published by removed crates.io account alonebeast002 as part of a 10+ crate campaign (2026-04-27 to 2026-04-30) targeting AWS Amazon Q Developer CLI internal crate names. All versions published at 99.x to win Cargo version resolution. Removed by crates.io admins. Malicious code in build.rs (executes at build time). Collects system and user data on the victim and exfiltrates to Telegram channel controlled by the attacker.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownamicontainedall (affected)

References

vendor

Browse GCVE Records

75,827 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›