VDB
GCVE-110-OSM-2025-319
GCVE-110-OSM-2025-319
Advisory PublishedCVSS 8.8/10
Indonesian threat actor (Dwi Bakti N Dev, a.k.a. Roy Html / Wolfes) openly publishing a portfolio of functional offensive cyberattack tools on GitHub and PyPI. Repos include working DDoS flood tools with hardcoded victim IPs, a spam/phishing email framework with explicit phishing templates, a full hacking toolkit installer (Metasploit, SQLMap, Hydra, BeEF, SET, RouterSploit), WiFi attack tools, and a follower-manipulation bot with leaked social media JWT credentials committed to a public repo. The lioncix PyPI package (v2.8.7) is published under the same author email.
DDOS-Attcak/DDOS/attck.py: 900-thread TCP socket flood against hardcoded victim 203.175.8.164:12160. landmark-ddos/ddos_landmark.py: socket flood against hardcoded victim 103.156.118.244:204. Spam-Email/spam_email.py: SpamEmailDesigner class with explicit phishing template type. TolHack/main.py: GitHubInstaller class auto-installs Metasploit, SQLMap, Hydra, Aircrack-ng, John the Ripper, BeEF, Social Engineer Toolkit, RouterSploit from GitHub. Followers-HeyReal/Token/Api.txt: plaintext HeyReal JWT credentials (e_id: dbd5280419c4a3501a9a2905c2e47ca7, thirdUid: 1298517713623085056). lioncix PyPI v2.8.7: branded PROFESSIONAL Hacker V2.8.7, author email dwibakti76@gmail.com.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
74,496 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.