VDB

GCVE-110-OSM-2026-9498

GCVE-110-OSM-2026-9498
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 31, 2026
This package self-identifies as a bug bounty / dependency confusion canary: the description says 'defensively registered unclaimed name, reported to the vendor,' the NOTICE string explicitly states 'authorised security test, coordinated with the vendor's security team through their bug bounty program,' and the beacon logic is transparent about collecting nothing beyond a DNS hit. The inflated version 9999.0.0 and oastify.com beacon are characteristic of dependency-confusion PoC tooling, not a stealthy attacker. However, the package does perform a real outbound DNS lookup and HTTP GET to a Burp Collaborator (oastify.com) subdomain on install, which is still unauthorized code execution on victim machines regardless of stated intent. The author account has zero other packages and no repository, which cannot confirm the 'authorized' claim. ENTRY setup.py (install-hook: install/develop/build override present) - setup.py Code Execution in setup.py DESTINATION - 1 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in setup.py: "oastify.com" - DNS Lookup in setup.py: "socket.getaddrinfo(" - Suspicious Domain in setup.py: "oastify.com" ADDITIONAL FINDINGS - Setup.py Command Override in setup.py: "cmdclass={ "egg_info": egg_info, "build_py": build_py, "install": install, "deve..." PAYLOAD FILES setup.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownasdk-plugin-legacyall (affected)

References

advisory
vendor

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›