VDB

GCVE-110-OSM-2026-9187

GCVE-110-OSM-2026-9187
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 18, 2026
This package presents as a legitimate penetration testing framework (similar in scope to Metasploit or Impacket) with clearly intentional offensive modules — C2, post-exploitation, credential dumping, SSRF test payloads, and OSINT enumeration. The CLI entrypoint (asta/cli.py) requires explicit user invocation with a target and contains extensive responsible-use commentary; there are no install hooks executing code against the installer. However, the package is from a brand-new, single-package publisher with two versions published within 25 minutes, and the `chai-max-browser-theft` signature match on `Chrome\User Data\Default\Login Data` references a known DPRK-linked stealer family. The IOC classifications are heavily inflated — social platform URLs in social_osint.py (Twitch, Pinterest, Steam) are legitimate OSINT targets, not exfil channels — but the real concern is whether this tool is a clean reimplementation or a trojanized package with active payload delivery. Without seeing the full C2 implant and cred_dump modules, the attacker model cannot be confirmed, but the new publisher + dual-use capabilities + known-malware signature pattern warrants manual review before dismissal. ENTRY asta/cli.py (console-script: asta=asta.cli:main) LOOT - Browser Data Theft in asta/phases/post_exploit/cred_dump.py: "Chrome\User Data\Default\Login Data" PERSISTENCE - Startup Persistence in asta/c2/__init__.py: ".profile" - Startup Persistence in asta/c2/implant/go/build.py: ".profile" - Startup Persistence in asta/c2/profiles/dns.py: ".profile" - Startup Persistence in asta/c2/server.py: ".profile" - Cron Job Persistence in asta/phases/post_exploit/privesc.py: "/etc/cron" DESTINATION - paste-site: https://pastebin.com/u/{username} (primary, plaintext) in asta/phases/passive/social_osint.py - custom-c2: http://evil.com/shell.txt? (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://169.254.169.254/latest/meta-data/ (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://169.254.169.254/latest/meta-data/iam/security-credentials/ (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://169.254.169.254/latest/user-data (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://169.254.169.254/latest/meta-data/iam/info (plaintext) in asta/phases/exploit/web_attacks.py - custom-c2: http://metadata.google.internal/computeMetadata/v1/ (plaintext) in asta/phases/exploit/web_attacks.py (+38 more) EXFIL - Reverse Shell in asta/phases/exploit/payload_gen.py: "/bin/sh -i" - OAST/Interactsh Exfiltration in asta/phases/exploit/web_attacks.py: "burpcollaborator.net" - Sensitive File Access in asta/phases/post_exploit/cred_dump.py: ""~/.ssh/id_rsa"" - Data Encoding for Exfiltration in asta/c2/encrypt.py: "base64.b64encode(" - Data Encoding for Exfiltration in asta/c2/server.py: "json.dumps({"e": "bad_request"}).encode" - Git Configuration Access in asta/phases/active/web_enum.py: ".git/config" - Git Configuration Access in asta/phases/enumeration/vuln_checks.py: ".git/config" - Data Encoding for Exfiltration in asta/phases/exploit/payload_gen.py: "base64.b64encode(" (+7 more) OBFUSCATION - Hex Encoded Strings in asta/phases/active/udp_scanner.py: ""\x30\x19\x02\x01\x01\x04\x06\x70\x75\x62\x6c\x69\x63\xa0\x0c\x02\x01\x00\x02\x0..." - Unicode Escape Obfuscation in asta/phases/active/udp_scanner.py: "\x00\x01\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x03" ADDITIONAL FINDINGS - Chai-Max Browser Data Theft in asta/phases/post_exploit/cred_dump.py: "Chrome\User Data\Default\Login Data" - Shell Command Execution in asta/c2/implant/go/build.py: "subprocess.run(" - Rapid Version Publishing PAYLOAD FILES asta/phases/post_exploit/cred_dump.py (+ asta/phases/exploit/payload_gen.py) INDICATORS (IOCs) - ipv4: 119.0.0.0, 239.255.255.250, 6.5.0.1, 12.2.1.3, 12.2.1.4 - urls: https://console.groq.com, https://openrouter.ai/keys, https://platform.deepseek.com/api_keys, http://127.0.0.1:8080`, http://p1:8080 (+17 more) - domains: console.groq.com, platform.deepseek.com, crt.sh, Hunter.io, api.groq.com (+10 more) - emails: evil.com@evil.com, local-part@domain.tld, user@host.tld, user.name@host.co.uk, image@2x.png - payloadFileHash: 56540a4acbb2c414a77dd5e04da10c13ae61fba891679d11214a9898d4117c7d

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownasta-pentestall (affected)

References

vendor

Browse GCVE Records

75,801 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›