VDB

GCVE-110-OSM-2026-8021

GCVE-110-OSM-2026-8021
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 14, 2026
Malicious package detected. Behaviors: data exfiltration, code execution. DESTINATION - custom-c2: https://118649d8f9d040aa7c55e8da95deaa49.r2.cloudflarestorage.com (primary, decoded) in ryry/utils.py - custom-c2: 118649d8f9d040aa7c55e8da95deaa49.r2.cloudflarestorage.com (decoded) in ryry/utils.py - custom-c2: https://{domain (plaintext) in ryry/ryry_webapi.py - custom-c2: https://{bucket (plaintext) in ryry/ryry_webapi.py - custom-c2: https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=1b006560-7012-4bf0-8c5e-a23830bc0a0b (plaintext) in ryry/taskUtils.py - custom-c2: https://qyapi.weixin.qq.com/cgi-bin/webhook/upload_media?key={webHookKey (plaintext) in ryry/taskUtils.py - custom-c2: https://api.mekoapp.com/upload/create (plaintext) in ryry/upload.py - custom-c2: https://res.zjtemplate.com (plaintext) in ryry/upload.py (+31 more) EXFIL - Data Encoding for Exfiltration in ryry/ryry_webapi.py: "base64.b64encode(" - Data Encoding for Exfiltration in ryry/taskUtils.py: "base64.b64encode(" - Data Encoding for Exfiltration in ryry/upload.py: "base64.b64encode(" - Data Encoding for Exfiltration in ryry/utils.py: "base64.b64encode(" - System Information Collection in ryry/daemon_manager.py: "platform.system()" - System Information Collection in ryry/main.py: "socket.gethostname()" - System Information Collection in ryry/proxy/binary.py: "platform.system()" - System Information Collection in ryry/ryry_server_socket.py: "socket.gethostname()" (+10 more) OBFUSCATION - Decoded Base64 Content in ryry/utils.py (x5) - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Shell Command Execution in ryry/daemon_manager.py: "subprocess.run(" - Silent Process Execution in ryry/proxy/manager.py: "stdout=subprocess.DEVNULL" - Shell Command Variable Setup in ryry/utils.py: "Windows': cmd = "ipconfig /all" output = subprocess.check_output(cmd, sh" - Brand New Package - Rapid Version Publishing PAYLOAD FILES ryry/utils.py INDICATORS (IOCs) - urls: http://scripts.sil.org/OFL, http://127.0.0.1:{controller_port, http://127.0.0.1:{self._controller_port, http://{username - domains: scripts.sil.org, dalipen.com, mekoapp.com, r2.cloudflarestorage.com - sha256Hashes: 5d90ebe9057b2d996ba4bae237f4a277101d72a923117b4ae0dd97d0c7dc584f, 3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986, b922f6fc90a232b9265db1cc9c5206fee8479dc2047bb037ebf09bc3c9e3b352, ab33dead65aaa95bc03b722f155d95f1003ac00517de6726e9b8d56ef9bbec92, 87db0c6660a9557a901b5750f997967e71d8c0af07ea1d1dd4d04c28da7f7e6f (+11 more) - payloadFileHash: e126810821a4984fc288cd31b38d92fd034f7798b11b1f3195155e849f187519

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownryry-cliall (affected)

References

vendor

Browse GCVE Records

75,792 records in the GCVE database · Updated August 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›