VDB
GCVE-110-OSM-2026-10766
GCVE-110-OSM-2026-10766
Advisory PublishedCVSS 5.4/10
This package is designed so that users can abuse the Tiktok platform. However, it is not malware itself and does not include any malicious behaviour outside its intended function, which in part is meant to violate TikTok terms and services.
We are marking this as INFO as organizations should not install this package
ENTRY
TIK_afrit/__init__.py (module-import: 8)
DESTINATION
- 28 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in TIK_afrit/AFRI.py: "binascii.hexlify("
- Data Encoding for Exfiltration in TIK_afrit/Bogus.py: "base64.b64encode("
- Dynamic C2 Endpoint Construction in TIK_afrit/Taiwn.py: ""S.","簡郭阿桃","小金","中情劇劇","艾登里長Aiden","柏偉","Nina☁️","理財爸爸","攝影小學堂","雪倫的隱藏版生活","阿欣"..."
- Data Encoding for Exfiltration in TIK_afrit/draver_id.py: "binascii.hexlify("
- Data Encoding for Exfiltration in TIK_afrit/edata.py: "base64.b64encode("
- Network Request in TIK_afrit/AFRI.py: "requests.post("
- Network Request in TIK_afrit/draver_id_log.py: "requests.post("
- Network Request in TIK_afrit/tiktok.py: "requests.post("
OBFUSCATION
- Unicode Escape Obfuscation in TIK_afrit/Arg.py: "\xac\x1a\xda\xae\x95\xa7\xaf\x94\xa5\x11"
- Base64 Encoded Payload in TIK_afrit/WEP.py: ""BAzd87PjF1lXaKcxXqwZ8Wy01sVNGfAwG5ZXAlgHtuEX7cR7JLPjj59FcUGzOTw8NjfjyIAFE91Wb1B..."
ADDITIONAL FINDINGS
- Campaign marker: TeamPCP March 2026 Cloud Campaign in TIK_afrit/domain.py: "fa_IR"
- Brand New Package
PAYLOAD FILES
TIK_afrit/AFRI.py (+ TIK_afrit/Bogus.py, TIK_afrit/Taiwn.py)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tiktok-afriton | all (affected) | — |
Browse GCVE Records
805 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.