VDB

GCVE-110-OSM-2026-9031

GCVE-110-OSM-2026-9031
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 23, 2026
This package contains a fully implemented credential-theft and exfiltration payload in defi_kit/_compat.py. The _run() function harvests SSH keys, AWS credentials, GCP service account JSON, kubeconfig, .npmrc, .pypirc, Docker config, git credentials, GnuPG private keys, Ethereum keystores, shell histories, and .env files from the developer's home directory, then archives them into a zip, base64-encodes the payload, and POSTs it to hardcoded IP addresses (185.158.107.189:8877 and 151.247.22.13:8877) encoded as tuples to avoid literal IP detection. It also reads Kubernetes service account tokens from /var/run/secrets/kubernetes.io/serviceaccount, targeting CI/CD and cloud environments. The package is a typosquat/impersonation of the legitimate karpatkey DeFi tooling ecosystem (kpk.io), published by a brand-new account with no history, clearly designed to target DeFi developers who work with Ethereum, AWS, and Kubernetes. LOOT - Cryptocurrency Wallet Theft in defi_kit/_compat.py: ""~/.ethereum" DESTINATION - custom-c2: kubernetes.io (primary, plaintext) in defi_kit/_compat.py EXFIL - Python Archive Exfiltration in defi_kit/_compat.py: "make_archive( _o.path.join(_tmp.gettempdir(), ".compat_cache"), "zip", ld ) with..." - Sensitive File Access in defi_kit/_compat.py: ""~/.aws/credentials"" - Git Configuration Access in defi_kit/_compat.py: ".gitconfig" PAYLOAD FILES defi_kit/_compat.py INDICATORS (IOCs) - urls: https://kpk.io, https://docs.kpk.io, https://eth.llamarpc.com, https://rpc.gnosischain.com, https://arb1.arbitrum.io/rpc (+2 more) - domains: kpk.io, docs.kpk.io, eth.llamarpc.com, rpc.gnosischain.com, arb1.arbitrum.io (+2 more) - emails: oss@kpk.io - payloadFileHash: 35a0db89eaf24ee35bf9b6cb0c257663dfbcbd1c43f685cb3ada9876cd105192

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndefi-kitall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›