VDB
GCVE-110-OSM-2026-9569
GCVE-110-OSM-2026-9569
Advisory PublishedCVSS 5.4/10
The two base64 strings in aiassistcore/workspace.py decode to cryptocurrency address validation regexes — specifically Bitcoin (bc1/1/3 prefix patterns) and Litecoin (L/M/ltc1 prefix patterns). While the decoded content is technically benign regex, base64-encoding regex literals in a published library has no legitimate purpose and is consistent with an early stage of a crypto-clipper or address-validation component whose exfiltration logic may have been stripped from this version or lives elsewhere at runtime. The package has zero metadata (no description, no repository, no author) — a classic burner-account shape — and the package name 'aiassistcore' is a generic AI-themed namespace typical of dependency-confusion or initial-access lure packages. No network calls, hooks, or credential reads were detected, so a full malicious verdict is not warranted, but the combination of obfuscated crypto address patterns and minimal metadata warrants manual review.
OBFUSCATION
- Base64 Encoded Payload in aiassistcore/workspace.py: ""XigxWzEtOUEtSEotTlAtWmEta20tel17MjUsMzR9fDNbMS05QS1ISi1OUC1aYS1rbS16XXsyNSwzNH1..."
- Decoded Base64 Content in aiassistcore/workspace.py (x17)
PAYLOAD FILES
aiassistcore/workspace.py
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | aiassistcore | all (affected) | — |
Aliases
Browse GCVE Records
67,517 records in the GCVE database · Updated August 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.