VDB
GCVE-110-OSM-2026-9186
GCVE-110-OSM-2026-9186
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code.
ENTRY
PIL/__init__.py (module-import: 64)
PERSISTENCE
- Startup Persistence in PIL/ImageCms.py: ".profile"
DESTINATION
- custom-c2: new.im (primary, plaintext) in PIL/Image.py
- custom-c2: palette.im (plaintext) in PIL/Image.py
- custom-c2: mask.im (plaintext) in PIL/Image.py
- custom-c2: im1.im (plaintext) in PIL/Image.py
EXFIL
- Corporate Environment Targeting in PIL/Image.py: "tmodetype(mode): msg = "mode mismatch"
OBFUSCATION
- Hex Encoded Strings in PIL/WalImageFile.py: ""\x01\x01\x01\x0b\x0b\x0b\x12\x12\x12\x17\x17\x17\x1b\x1b\x1b\x1e""
- Unicode Escape Obfuscation in PIL/WalImageFile.py: "\x01\x01\x01\x0b\x0b\x0b\x12\x12\x12\x17\x17\x17\x1b\x1b\x1b\x1e"
- Decoded Hex Escape Content in PIL/WalImageFile.py (x7)
ADDITIONAL FINDINGS
- Silent Process Execution in PIL/EpsImagePlugin.py: "stdout=subprocess.DEVNULL"
- Shell Command Execution in PIL/GifImagePlugin.py: "subprocess.Popen("
- Brand New Package
PAYLOAD FILES
PIL/WalImageFile.py
INDICATORS (IOCs)
- ipv4: 7.9.2.2
- ipv6: 3::, 1::
- urls: https://bugs.ghostscript.com/show_bug.cgi?id=698272, https://www.matthewflickinger.com/lab/whatsinagif/bits_and_bytes.asp, https://www.cazabon.com, https://www.cazabon.com/pyCMS, https://www.littlecms.com (+15 more)
- domains: oss.sgi.com, bugs.ghostscript.com, www.adobe.com, partners.adobe.com, www.matthewflickinger.com (+19 more)
- emails: jerome@leclan.ch, kevin@cazabon.com, aurelien.ballier@cyclonit.com, gcoats@labiris.er.usgs.gov, gregc@cgl.ucsf.edu (+2 more)
- payloadFileHash: 759db52034124f6a3b63b800f90c51cf0231d9a88e6c63b5528b2075dd84a497
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | rasterkit | all (affected) | — |
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.