VDB

GCVE-110-OSM-2026-10770

GCVE-110-OSM-2026-10770
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published August 19, 2026
This package is a hollow stub impersonating Tencent's legitimate Hunyuan 3D project, containing no actual AI/3D functionality — only metadata and a trivial __init__.py that returns a website URL. The publisher 'dallen' has 34 packages, all version 0.1.0, all AI-branded stubs pointing to various third-party websites (hunyuan-3d.org, seedream5ai.org, etc.), which is a hallmark of SEO squatting or typosquatting campaigns designed to hijack search traffic or establish PyPI presence for later weaponization. The domain hunyuan-3d.org is not the legitimate Tencent project domain (tencent.com or github.com/Tencent/Hunyuan3D). While no active malicious payload is present in this version, the pattern of mass stub publishing under AI brand names is consistent with a placeholder campaign that could deliver malicious updates or simply drive traffic to affiliate/phishing sites. ENTRY hunyuan_3d/__init__.py (module-import: 17)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownhunyuan-3dall (affected)

References

vendor

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›