VDB

GCVE-110-OSM-2026-9549

GCVE-110-OSM-2026-9549
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 1, 2026
The package self-identifies as an authorized VDP dependency-confusion test in its description, and the evidence is structurally consistent with that claim: the version is artificially inflated to 99999.0.1 (a canonical dependency-confusion technique), and the callback URL 'http://167.233.212.138/cb/db27bcff144c059f/nvtorch_oot_nightly' follows the path structure typical of OAST/beacon tracking used in authorized internal-package probing rather than a stealer C2 (no credential harvesting, no exfil payload, no obfuscation). The IP 167.233.212.138 is classified as C2 by the IOC classifier, but without corroborating exfiltration or persistence findings and given the explicit self-declaration, this is more consistent with a ping-home beacon than a compromised package. Submitting a confirmed VDP test to OSM would pollute the database; the correct action is to not submit. DESTINATION - 2 c2 (ipv4, urls) (values recorded in verified_iocs) EXFIL - Suspicious Domain in setup.py: "http://167.233.212.138"

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownnvtorch-oot-nightlyall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›