VDB
GCVE-110-OSM-2026-8021
GCVE-110-OSM-2026-8021
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration, code execution.
DESTINATION
- custom-c2: https://118649d8f9d040aa7c55e8da95deaa49.r2.cloudflarestorage.com (primary, decoded) in ryry/utils.py
- custom-c2: 118649d8f9d040aa7c55e8da95deaa49.r2.cloudflarestorage.com (decoded) in ryry/utils.py
- custom-c2: https://{domain (plaintext) in ryry/ryry_webapi.py
- custom-c2: https://{bucket (plaintext) in ryry/ryry_webapi.py
- custom-c2: https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=1b006560-7012-4bf0-8c5e-a23830bc0a0b (plaintext) in ryry/taskUtils.py
- custom-c2: https://qyapi.weixin.qq.com/cgi-bin/webhook/upload_media?key={webHookKey (plaintext) in ryry/taskUtils.py
- custom-c2: https://api.mekoapp.com/upload/create (plaintext) in ryry/upload.py
- custom-c2: https://res.zjtemplate.com (plaintext) in ryry/upload.py
(+31 more)
EXFIL
- Data Encoding for Exfiltration in ryry/ryry_webapi.py: "base64.b64encode("
- Data Encoding for Exfiltration in ryry/taskUtils.py: "base64.b64encode("
- Data Encoding for Exfiltration in ryry/upload.py: "base64.b64encode("
- Data Encoding for Exfiltration in ryry/utils.py: "base64.b64encode("
- System Information Collection in ryry/daemon_manager.py: "platform.system()"
- System Information Collection in ryry/main.py: "socket.gethostname()"
- System Information Collection in ryry/proxy/binary.py: "platform.system()"
- System Information Collection in ryry/ryry_server_socket.py: "socket.gethostname()"
(+10 more)
OBFUSCATION
- Decoded Base64 Content in ryry/utils.py (x5)
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Shell Command Execution in ryry/daemon_manager.py: "subprocess.run("
- Silent Process Execution in ryry/proxy/manager.py: "stdout=subprocess.DEVNULL"
- Shell Command Variable Setup in ryry/utils.py: "Windows': cmd = "ipconfig /all" output = subprocess.check_output(cmd, sh"
- Brand New Package
- Rapid Version Publishing
PAYLOAD FILES
ryry/utils.py
INDICATORS (IOCs)
- urls: http://scripts.sil.org/OFL, http://127.0.0.1:{controller_port, http://127.0.0.1:{self._controller_port, http://{username
- domains: scripts.sil.org, dalipen.com, mekoapp.com, r2.cloudflarestorage.com
- sha256Hashes: 5d90ebe9057b2d996ba4bae237f4a277101d72a923117b4ae0dd97d0c7dc584f, 3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986, b922f6fc90a232b9265db1cc9c5206fee8479dc2047bb037ebf09bc3c9e3b352, ab33dead65aaa95bc03b722f155d95f1003ac00517de6726e9b8d56ef9bbec92, 87db0c6660a9557a901b5750f997967e71d8c0af07ea1d1dd4d04c28da7f7e6f (+11 more)
- payloadFileHash: e126810821a4984fc288cd31b38d92fd034f7798b11b1f3195155e849f187519
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ryry-cli | all (affected) | — |
Browse GCVE Records
75,792 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.