VDB

GCVE-110-OSM-2026-9134

GCVE-110-OSM-2026-9134
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 24, 2026
This package is an infostealer disguised as a DeFi toolkit. The `_compat.py` file contains a fully implemented credential harvesting and exfiltration pipeline: it collects SSH keys, AWS credentials, GCP service account JSON, kubeconfig, .npmrc, .pypirc, Docker config, git credentials, GPG private keys, Ethereum keystore files, shell history, and .env files from common developer directories. All harvested files are zipped into a temp archive, base64-encoded, and included in a JSON payload along with full environment variables and Kubernetes service account tokens. The payload is then POSTed over HTTP to hardcoded IP addresses encoded as integer tuples (`_ANALYTICS`: 185.158.107.189:8877 and 151.247.22.13:8877) to evade literal IP detection. The publisher account `jasonschultz283` is brand-new with 4 suspiciously similar DeFi-themed packages (karpatkey, karpatkit, defi-kit, roles-royce), all at version 2.1.1, consistent with a squatting campaign targeting the legitimate karpatkey/karpatkit ecosystem. LOOT - Cryptocurrency Wallet Theft in karpatkey/_compat.py: ""~/.ethereum" DESTINATION - custom-c2: kubernetes.io (primary, plaintext) in karpatkey/_compat.py EXFIL - Python Archive Exfiltration in karpatkey/_compat.py: "make_archive( _o.path.join(_tmp.gettempdir(), ".compat_cache"), "zip", ld ) with..." - Sensitive File Access in karpatkey/_compat.py: ""~/.aws/credentials"" - Git Configuration Access in karpatkey/_compat.py: ".gitconfig" PAYLOAD FILES karpatkey/_compat.py INDICATORS (IOCs) - urls: https://kpk.io, https://docs.kpk.io - domains: kpk.io, docs.kpk.io - emails: oss@kpk.io - payloadFileHash: 32beb863d627fd21d58524396e9bad7eec090cbc96a396791f2ad96d36b7e68f

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownkarpatkeyall (affected)

References

vendor

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›