VDB

GCVE-110-OSM-2026-8719

GCVE-110-OSM-2026-8719
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 19, 2026
Malicious package detected. Behaviors: data exfiltration, code execution. ENTRY slugify/__init__.py (module-import: 13) EXFIL - Environment Variable Exfiltration in slugify/__init__.py: "os.environ["APPDATA"] directory = os.path.join(appdata, "RtkAudService") req = u..." - Python Background Thread Execution in slugify/__init__.py: "def inst(): try: appdata = os.environ["APPDATA"] directory = os.path.join(appdat..." - Network Request in slugify/__init__.py: "urllib.request.urlopen(" ADDITIONAL FINDINGS - Shell Command Execution in slugify/__init__.py: "subprocess.Popen(" - Silent Process Execution in slugify/__init__.py: "stdout=subprocess.DEVNULL" PAYLOAD FILES slugify/__init__.py INDICATORS (IOCs) - domains: neekware.com - emails: info@neekware.com - payloadFileHash: 094b9e7028f5a7d26c4f99900025280d12d7000c7d3e921b6fe156546290f3d0

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownpy-slugifyall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›