VDB
GCVE-110-OSM-2026-9187
GCVE-110-OSM-2026-9187
Advisory PublishedCVSS 5.4/10
This package presents as a legitimate penetration testing framework (similar in scope to Metasploit or Impacket) with clearly intentional offensive modules — C2, post-exploitation, credential dumping, SSRF test payloads, and OSINT enumeration. The CLI entrypoint (asta/cli.py) requires explicit user invocation with a target and contains extensive responsible-use commentary; there are no install hooks executing code against the installer. However, the package is from a brand-new, single-package publisher with two versions published within 25 minutes, and the `chai-max-browser-theft` signature match on `Chrome\User Data\Default\Login Data` references a known DPRK-linked stealer family. The IOC classifications are heavily inflated — social platform URLs in social_osint.py (Twitch, Pinterest, Steam) are legitimate OSINT targets, not exfil channels — but the real concern is whether this tool is a clean reimplementation or a trojanized package with active payload delivery. Without seeing the full C2 implant and cred_dump modules, the attacker model cannot be confirmed, but the new publisher + dual-use capabilities + known-malware signature pattern warrants manual review before dismissal.
ENTRY
asta/cli.py (console-script: asta=asta.cli:main)
LOOT
- Browser Data Theft in asta/phases/post_exploit/cred_dump.py: "Chrome\User Data\Default\Login Data"
PERSISTENCE
- Startup Persistence in asta/c2/__init__.py: ".profile"
- Startup Persistence in asta/c2/implant/go/build.py: ".profile"
- Startup Persistence in asta/c2/profiles/dns.py: ".profile"
- Startup Persistence in asta/c2/server.py: ".profile"
- Cron Job Persistence in asta/phases/post_exploit/privesc.py: "/etc/cron"
DESTINATION
- paste-site: https://pastebin.com/u/{username} (primary, plaintext) in asta/phases/passive/social_osint.py
- custom-c2: http://evil.com/shell.txt? (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://169.254.169.254/latest/meta-data/ (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://169.254.169.254/latest/meta-data/iam/security-credentials/ (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://169.254.169.254/latest/user-data (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://169.254.169.254/latest/meta-data/iam/info (plaintext) in asta/phases/exploit/web_attacks.py
- custom-c2: http://metadata.google.internal/computeMetadata/v1/ (plaintext) in asta/phases/exploit/web_attacks.py
(+38 more)
EXFIL
- Reverse Shell in asta/phases/exploit/payload_gen.py: "/bin/sh -i"
- OAST/Interactsh Exfiltration in asta/phases/exploit/web_attacks.py: "burpcollaborator.net"
- Sensitive File Access in asta/phases/post_exploit/cred_dump.py: ""~/.ssh/id_rsa""
- Data Encoding for Exfiltration in asta/c2/encrypt.py: "base64.b64encode("
- Data Encoding for Exfiltration in asta/c2/server.py: "json.dumps({"e": "bad_request"}).encode"
- Git Configuration Access in asta/phases/active/web_enum.py: ".git/config"
- Git Configuration Access in asta/phases/enumeration/vuln_checks.py: ".git/config"
- Data Encoding for Exfiltration in asta/phases/exploit/payload_gen.py: "base64.b64encode("
(+7 more)
OBFUSCATION
- Hex Encoded Strings in asta/phases/active/udp_scanner.py: ""\x30\x19\x02\x01\x01\x04\x06\x70\x75\x62\x6c\x69\x63\xa0\x0c\x02\x01\x00\x02\x0..."
- Unicode Escape Obfuscation in asta/phases/active/udp_scanner.py: "\x00\x01\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x03"
ADDITIONAL FINDINGS
- Chai-Max Browser Data Theft in asta/phases/post_exploit/cred_dump.py: "Chrome\User Data\Default\Login Data"
- Shell Command Execution in asta/c2/implant/go/build.py: "subprocess.run("
- Rapid Version Publishing
PAYLOAD FILES
asta/phases/post_exploit/cred_dump.py (+ asta/phases/exploit/payload_gen.py)
INDICATORS (IOCs)
- ipv4: 119.0.0.0, 239.255.255.250, 6.5.0.1, 12.2.1.3, 12.2.1.4
- urls: https://console.groq.com, https://openrouter.ai/keys, https://platform.deepseek.com/api_keys, http://127.0.0.1:8080`, http://p1:8080 (+17 more)
- domains: console.groq.com, platform.deepseek.com, crt.sh, Hunter.io, api.groq.com (+10 more)
- emails: evil.com@evil.com, local-part@domain.tld, user@host.tld, user.name@host.co.uk, image@2x.png
- payloadFileHash: 56540a4acbb2c414a77dd5e04da10c13ae61fba891679d11214a9898d4117c7d
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | asta-pentest | all (affected) | — |
Browse GCVE Records
75,801 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.