VDB

GCVE-110-OSM-2026-9569

GCVE-110-OSM-2026-9569
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 31, 2026
The two base64 strings in aiassistcore/workspace.py decode to cryptocurrency address validation regexes — specifically Bitcoin (bc1/1/3 prefix patterns) and Litecoin (L/M/ltc1 prefix patterns). While the decoded content is technically benign regex, base64-encoding regex literals in a published library has no legitimate purpose and is consistent with an early stage of a crypto-clipper or address-validation component whose exfiltration logic may have been stripped from this version or lives elsewhere at runtime. The package has zero metadata (no description, no repository, no author) — a classic burner-account shape — and the package name 'aiassistcore' is a generic AI-themed namespace typical of dependency-confusion or initial-access lure packages. No network calls, hooks, or credential reads were detected, so a full malicious verdict is not warranted, but the combination of obfuscated crypto address patterns and minimal metadata warrants manual review. OBFUSCATION - Base64 Encoded Payload in aiassistcore/workspace.py: ""XigxWzEtOUEtSEotTlAtWmEta20tel17MjUsMzR9fDNbMS05QS1ISi1OUC1aYS1rbS16XXsyNSwzNH1..." - Decoded Base64 Content in aiassistcore/workspace.py (x17) PAYLOAD FILES aiassistcore/workspace.py

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownaiassistcoreall (affected)

References

advisory
vendor

Browse GCVE Records

67,517 records in the GCVE database · Updated August 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›