VDB

GCVE-110-OSM-2026-9186

GCVE-110-OSM-2026-9186
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 21, 2026
Malicious package detected. Behaviors: data exfiltration, code execution, obfuscated code. ENTRY PIL/__init__.py (module-import: 64) PERSISTENCE - Startup Persistence in PIL/ImageCms.py: ".profile" DESTINATION - custom-c2: new.im (primary, plaintext) in PIL/Image.py - custom-c2: palette.im (plaintext) in PIL/Image.py - custom-c2: mask.im (plaintext) in PIL/Image.py - custom-c2: im1.im (plaintext) in PIL/Image.py EXFIL - Corporate Environment Targeting in PIL/Image.py: "tmodetype(mode): msg = "mode mismatch" OBFUSCATION - Hex Encoded Strings in PIL/WalImageFile.py: ""\x01\x01\x01\x0b\x0b\x0b\x12\x12\x12\x17\x17\x17\x1b\x1b\x1b\x1e"" - Unicode Escape Obfuscation in PIL/WalImageFile.py: "\x01\x01\x01\x0b\x0b\x0b\x12\x12\x12\x17\x17\x17\x1b\x1b\x1b\x1e" - Decoded Hex Escape Content in PIL/WalImageFile.py (x7) ADDITIONAL FINDINGS - Silent Process Execution in PIL/EpsImagePlugin.py: "stdout=subprocess.DEVNULL" - Shell Command Execution in PIL/GifImagePlugin.py: "subprocess.Popen(" - Brand New Package PAYLOAD FILES PIL/WalImageFile.py INDICATORS (IOCs) - ipv4: 7.9.2.2 - ipv6: 3::, 1:: - urls: https://bugs.ghostscript.com/show_bug.cgi?id=698272, https://www.matthewflickinger.com/lab/whatsinagif/bits_and_bytes.asp, https://www.cazabon.com, https://www.cazabon.com/pyCMS, https://www.littlecms.com (+15 more) - domains: oss.sgi.com, bugs.ghostscript.com, www.adobe.com, partners.adobe.com, www.matthewflickinger.com (+19 more) - emails: jerome@leclan.ch, kevin@cazabon.com, aurelien.ballier@cyclonit.com, gcoats@labiris.er.usgs.gov, gregc@cgl.ucsf.edu (+2 more) - payloadFileHash: 759db52034124f6a3b63b800f90c51cf0231d9a88e6c63b5528b2075dd84a497

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownrasterkitall (affected)

References

vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›