VDB

GCVE-110-OSM-2026-9497

GCVE-110-OSM-2026-9497
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 31, 2026
This package self-identifies as a bug bounty / dependency confusion security test: the description, the NOTICE string in setup.py, and the docstring all explicitly state it is an 'authorised security test, coordinated with the vendor's security team through their bug bounty program.' The beacon mechanism (DNS + HTTP to sxtgv4ubumzow86agp0q3krbh2nvbnzc.oastify.com) and inflated version 9999.0.0 are classic dependency-confusion canary patterns. Per adjudication rules, self-identified bounty/test packages should be treated as suspicious-but-benign rather than malicious, because submitting them to OSM pollutes the database. The OAST endpoint and cmdclass overrides are real and functional, but the stated purpose and the absence of any credential/env harvesting are consistent with a legitimate canary, not an attacker payload. ENTRY setup.py (install-hook: install/develop/build override present) - setup.py Code Execution in setup.py DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in setup.py: "oastify.com" - DNS Lookup in setup.py: "socket.getaddrinfo(" - Suspicious Domain in setup.py: "oastify.com" ADDITIONAL FINDINGS - Setup.py Command Override in setup.py: "cmdclass={ "egg_info": egg_info, "build_py": build_py, "install": install, "deve..." PAYLOAD FILES setup.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownasdk-plugin-alphagenall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›