VDB

GCVE-110-OSM-2026-8492

GCVE-110-OSM-2026-8492
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 27, 2026
Dependency-confusion/typosquat crate published by removed crates.io account alonebeast002 as part of a 10+ crate campaign (2026-04-27 to 2026-04-30) targeting AWS Amazon Q Developer CLI internal crate names. All versions published at 99.x to win Cargo version resolution. Removed by crates.io admins. Malicious code in build.rs (executes at build time). Collects system and user data on the victim and exfiltrates to Telegram channel controlled by the attacker.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownunicode-genall (affected)

References

vendor

Browse GCVE Records

75,788 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›