VDB
GCVE-110-OSM-2026-9498
GCVE-110-OSM-2026-9498
Advisory PublishedCVSS 5.4/10
This package self-identifies as a bug bounty / dependency confusion canary: the description says 'defensively registered unclaimed name, reported to the vendor,' the NOTICE string explicitly states 'authorised security test, coordinated with the vendor's security team through their bug bounty program,' and the beacon logic is transparent about collecting nothing beyond a DNS hit. The inflated version 9999.0.0 and oastify.com beacon are characteristic of dependency-confusion PoC tooling, not a stealthy attacker. However, the package does perform a real outbound DNS lookup and HTTP GET to a Burp Collaborator (oastify.com) subdomain on install, which is still unauthorized code execution on victim machines regardless of stated intent. The author account has zero other packages and no repository, which cannot confirm the 'authorized' claim.
ENTRY
setup.py (install-hook: install/develop/build override present)
- setup.py Code Execution in setup.py
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in setup.py: "oastify.com"
- DNS Lookup in setup.py: "socket.getaddrinfo("
- Suspicious Domain in setup.py: "oastify.com"
ADDITIONAL FINDINGS
- Setup.py Command Override in setup.py: "cmdclass={ "egg_info": egg_info, "build_py": build_py, "install": install, "deve..."
PAYLOAD FILES
setup.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | asdk-plugin-legacy | all (affected) | — |
Aliases
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.