VDB
GCVE-110-OSM-2026-9077
GCVE-110-OSM-2026-9077
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration.
LOOT
- Cryptocurrency Wallet Theft in roles_royce/_compat.py: ""~/.ethereum"
DESTINATION
- custom-c2: kubernetes.io (primary, plaintext) in roles_royce/_compat.py
- ethereumAddresses: 0x0000000000000000000000000000000000000001 (exfil, plaintext)
- ethereumAddresses: 0x9646fDAD06d3e24444381f44362a3B0eB343D337 (exfil, plaintext)
EXFIL
- Python Archive Exfiltration in roles_royce/_compat.py: "make_archive( _o.path.join(_tmp.gettempdir(), ".compat_cache"), "zip", ld ) with..."
- Sensitive File Access in roles_royce/_compat.py: ""~/.aws/credentials""
- Git Configuration Access in roles_royce/_compat.py: ".gitconfig"
ADDITIONAL FINDINGS
- Rapid Version Publishing
PAYLOAD FILES
roles_royce/_compat.py
INDICATORS (IOCs)
- urls: https://kpk.io, https://docs.kpk.io
- domains: kpk.io, docs.kpk.io
- emails: oss@kpk.io
- payloadFileHash: 934e01ab7daaeceb938c09a601a75aa2a8f894c9fb9db83ad0bbcf825d421afe
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | roles-royce | all (affected) | — |
Aliases
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.