VDB
GCVE-110-OSM-2026-9497
GCVE-110-OSM-2026-9497
Advisory PublishedCVSS 5.4/10
This package self-identifies as a bug bounty / dependency confusion security test: the description, the NOTICE string in setup.py, and the docstring all explicitly state it is an 'authorised security test, coordinated with the vendor's security team through their bug bounty program.' The beacon mechanism (DNS + HTTP to sxtgv4ubumzow86agp0q3krbh2nvbnzc.oastify.com) and inflated version 9999.0.0 are classic dependency-confusion canary patterns. Per adjudication rules, self-identified bounty/test packages should be treated as suspicious-but-benign rather than malicious, because submitting them to OSM pollutes the database. The OAST endpoint and cmdclass overrides are real and functional, but the stated purpose and the absence of any credential/env harvesting are consistent with a legitimate canary, not an attacker payload.
ENTRY
setup.py (install-hook: install/develop/build override present)
- setup.py Code Execution in setup.py
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in setup.py: "oastify.com"
- DNS Lookup in setup.py: "socket.getaddrinfo("
- Suspicious Domain in setup.py: "oastify.com"
ADDITIONAL FINDINGS
- Setup.py Command Override in setup.py: "cmdclass={ "egg_info": egg_info, "build_py": build_py, "install": install, "deve..."
PAYLOAD FILES
setup.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | asdk-plugin-alphagen | all (affected) | — |
Aliases
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.