VDB

GCVE-110-OSM-2026-9422

GCVE-110-OSM-2026-9422
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 30, 2026
On import, phabricator_client/__init__.py resolves 'lobohunter.duckdns.org' and opens a raw TCP socket to port 9999 — a textbook C2 beacon or reverse-shell initiation pattern. DuckDNS is an attacker-favored dynamic DNS provider because it allows free, anonymous subdomains that can be rapidly reassigned to new infrastructure. The package description is empty, no source repository exists, and five versions were published in two days under a suspiciously high version number (99.x), all consistent with a dependency-confusion or typosquatting campaign testing connectivity before deploying a full payload. The self-described 'placeholder package' label in the docstring is a social-engineering tell — legitimate placeholders do not establish outbound TCP connections to attacker-controlled DNS names. ENTRY phabricator_client/__init__.py (module-import: 9) EXFIL - DNS Lookup in phabricator_client/__init__.py: "socket.gethostbyname(" ADDITIONAL FINDINGS - Brand New Package PAYLOAD FILES phabricator_client/__init__.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownphabricator-clientall (affected)

References

advisory
vendor

Browse GCVE Records

76,198 records in the GCVE database · Updated August 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›