VDB
GCVE-110-OSM-2026-10770
GCVE-110-OSM-2026-10770
Advisory PublishedCVSS 5.4/10
This package is a hollow stub impersonating Tencent's legitimate Hunyuan 3D project, containing no actual AI/3D functionality — only metadata and a trivial __init__.py that returns a website URL. The publisher 'dallen' has 34 packages, all version 0.1.0, all AI-branded stubs pointing to various third-party websites (hunyuan-3d.org, seedream5ai.org, etc.), which is a hallmark of SEO squatting or typosquatting campaigns designed to hijack search traffic or establish PyPI presence for later weaponization. The domain hunyuan-3d.org is not the legitimate Tencent project domain (tencent.com or github.com/Tencent/Hunyuan3D). While no active malicious payload is present in this version, the pattern of mass stub publishing under AI brand names is consistent with a placeholder campaign that could deliver malicious updates or simply drive traffic to affiliate/phishing sites.
ENTRY
hunyuan_3d/__init__.py (module-import: 17)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | hunyuan-3d | all (affected) | — |
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.