VDB
GCVE-110-OSM-2026-9134
GCVE-110-OSM-2026-9134
Advisory PublishedCVSS 9.6/10
This package is an infostealer disguised as a DeFi toolkit. The `_compat.py` file contains a fully implemented credential harvesting and exfiltration pipeline: it collects SSH keys, AWS credentials, GCP service account JSON, kubeconfig, .npmrc, .pypirc, Docker config, git credentials, GPG private keys, Ethereum keystore files, shell history, and .env files from common developer directories. All harvested files are zipped into a temp archive, base64-encoded, and included in a JSON payload along with full environment variables and Kubernetes service account tokens. The payload is then POSTed over HTTP to hardcoded IP addresses encoded as integer tuples (`_ANALYTICS`: 185.158.107.189:8877 and 151.247.22.13:8877) to evade literal IP detection. The publisher account `jasonschultz283` is brand-new with 4 suspiciously similar DeFi-themed packages (karpatkey, karpatkit, defi-kit, roles-royce), all at version 2.1.1, consistent with a squatting campaign targeting the legitimate karpatkey/karpatkit ecosystem.
LOOT
- Cryptocurrency Wallet Theft in karpatkey/_compat.py: ""~/.ethereum"
DESTINATION
- custom-c2: kubernetes.io (primary, plaintext) in karpatkey/_compat.py
EXFIL
- Python Archive Exfiltration in karpatkey/_compat.py: "make_archive( _o.path.join(_tmp.gettempdir(), ".compat_cache"), "zip", ld ) with..."
- Sensitive File Access in karpatkey/_compat.py: ""~/.aws/credentials""
- Git Configuration Access in karpatkey/_compat.py: ".gitconfig"
PAYLOAD FILES
karpatkey/_compat.py
INDICATORS (IOCs)
- urls: https://kpk.io, https://docs.kpk.io
- domains: kpk.io, docs.kpk.io
- emails: oss@kpk.io
- payloadFileHash: 32beb863d627fd21d58524396e9bad7eec090cbc96a396791f2ad96d36b7e68f
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | karpatkey | all (affected) | — |
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.