Malicious code in gcli-control (PyPI)
The gcli-control package on PyPI contains malicious code that installs a host daemon capable of executing commands received from a shared JSON document. This daemon allows any party with write access to the document to execute arbitrary code remotely, including credential theft, keylogging, webcam capture, and privilege escalation. The package includes hardcoded default identifiers and a bypass mechanism that disables encryption, enabling unauthenticated remote code execution and full remote-access trojan capabilities. Multiple versions of the package are affected.
AI Analysis
Technical Summary
The gcli-control PyPI package installs and runs a host daemon (`python -m gcli host`) that polls a shared JSON document at api.npoint.io for commands. Commands are decrypted and executed on the host machine, with results posted back encrypted. The daemon uses a hardcoded default rendezvous bin ID shared across all default installations, and a bypass password disables AES-GCM encryption, allowing anonymous unauthenticated command injection. The command dispatcher exposes over 200 operations, including browser password and cookie theft, keylogging, webcam capture, shell history access, Wi-Fi password theft, screenshots, user credential manipulation, and persistence mechanisms via Windows Run keys, systemd services, cron jobs, and startup folder launchers. It also includes privilege escalation modules. This combination constitutes a full remote-access trojan controlled by any party who knows the default rendezvous bin, affecting versions 0.5.0, 0.11.1, 0.12.2, and 0.12.4.
Potential Impact
Any attacker who can write to the shared JSON document can remotely execute arbitrary code on all machines running the daemon with the default configuration. This includes stealing sensitive credentials and secrets, capturing keystrokes and webcam images, maintaining persistence on the host system, and escalating privileges. The threat enables complete host compromise and persistent remote access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or running the gcli-control package, especially versions 0.5.0, 0.11.1, 0.12.2, and 0.12.4. Remove any existing installations of this package and monitor for suspicious activity related to the daemon. Do not use the default rendezvous bin ID or the bypass password sentinel if overriding is possible.
Malicious code in gcli-control (PyPI)
Description
The gcli-control package on PyPI contains malicious code that installs a host daemon capable of executing commands received from a shared JSON document. This daemon allows any party with write access to the document to execute arbitrary code remotely, including credential theft, keylogging, webcam capture, and privilege escalation. The package includes hardcoded default identifiers and a bypass mechanism that disables encryption, enabling unauthenticated remote code execution and full remote-access trojan capabilities. Multiple versions of the package are affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The gcli-control PyPI package installs and runs a host daemon (`python -m gcli host`) that polls a shared JSON document at api.npoint.io for commands. Commands are decrypted and executed on the host machine, with results posted back encrypted. The daemon uses a hardcoded default rendezvous bin ID shared across all default installations, and a bypass password disables AES-GCM encryption, allowing anonymous unauthenticated command injection. The command dispatcher exposes over 200 operations, including browser password and cookie theft, keylogging, webcam capture, shell history access, Wi-Fi password theft, screenshots, user credential manipulation, and persistence mechanisms via Windows Run keys, systemd services, cron jobs, and startup folder launchers. It also includes privilege escalation modules. This combination constitutes a full remote-access trojan controlled by any party who knows the default rendezvous bin, affecting versions 0.5.0, 0.11.1, 0.12.2, and 0.12.4.
Potential Impact
Any attacker who can write to the shared JSON document can remotely execute arbitrary code on all machines running the daemon with the default configuration. This includes stealing sensitive credentials and secrets, capturing keystrokes and webcam images, maintaining persistence on the host system, and escalating privileges. The threat enables complete host compromise and persistent remote access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix or official guidance is available, avoid installing or running the gcli-control package, especially versions 0.5.0, 0.11.1, 0.12.2, and 0.12.4. Remove any existing installations of this package and monitor for suspicious activity related to the daemon. Do not use the default rendezvous bin ID or the bypass password sentinel if overriding is possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12502
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6a735741bf8831d539154cca
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:00:16 UTC
Last updated: 09/19/2026, 08:10:36 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.