VDB

GCVE-110-OSM-2026-8020

GCVE-110-OSM-2026-8020
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 14, 2026
Malicious package detected. DESTINATION - urls: https://movie.douban.com/subject/{id_ (c2, plaintext) - urls: https://biz.finance.sina.com.cn/suggest/lookup_n.php (c2, plaintext) - urls: https://finance.sina.com.cn (c2, plaintext) - urls: https://hq.sinajs.cn/rn=%s&list=%s (c2, plaintext) - urls: https://www.toutiao.com/hot-event/hot-board/ (c2, plaintext) - urls: https://weibo.com/newlogin?tabtype=weibo&gid=102803&openLoginLayer=0&url=https%3A%2F%2Fwww.weibo.com%2F (c2, plaintext) - domains: movie.douban.com (c2, plaintext) - domains: biz.finance.sina.com.cn (c2, plaintext) (+2 more) ADDITIONAL FINDINGS - Brand New Package INDICATORS (IOCs) - urls: https://www.reyxbo.com, https://opendata.baidu.com/data/inner, https://m.douban.com/rexxar/api/v2/subject/recent_hot/%s, https://movie.douban.com/%s/, https://finance.sina.com.cn/realstock/company/%s/nc.shtml (+3 more) - domains: www.reyxbo.com, 163.com, opendata.baidu.com, m.douban.com, s.weibo.com - emails: reyxbo@163.com

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownreycrawler1.0.7 (affected)

References

vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›