VDB

GCVE-110-OSM-2026-8714

GCVE-110-OSM-2026-8714
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published July 19, 2026
This package is a Telegram bot swarm tool designed for group flooding, chat takeover, and OSINT-based doxxing. This is a purpose-built Telegram abuse and doxxing toolkit published under a novelty anime theme to deflect scrutiny. ENTRY sankislayer/bot.py (console-script: "sankislayer=sankislayer.bot:main_run") DESTINATION - telegram-bot: 8670917633:AAHyYOvwq2J7KwP3m8UkG9jIWjY9V1suSLU (primary, plaintext) in sankislayer/bot.py - telegram-bot: 8814064963:AAGBY_20bjJuEm6GMI1iz0WzzP9orUI4Qps (plaintext) in sankislayer/bot.py - telegram-bot: 8856278072:AAEQLcRGPHMfxQoQpvVjB_5npBdJmgOU34g (plaintext) in sankislayer/bot.py - telegram-bot: 8806837748:AAGsZiBuRF4P9jS7U-83DkCaS3NuRpeyPOg (plaintext) in sankislayer/bot.py - telegram-bot: 8981300250:AAFtEgbpmxiT-5LF8HuQLvmi5Vf0bsja4Ag (plaintext) in sankislayer/bot.py - telegram-bot: 8940953835:AAEK-9Ph5K8CEkDFzTYkhOGCPOmC4nTj96E (plaintext) in sankislayer/bot.py - telegram-bot: 8992213913:AAGrwwfJlz1Sxb7g4U30aH6XamJ51wbMZp0 (plaintext) in sankislayer/bot.py - telegram-bot: 8973071671:AAF1ErUkYkn3wEQLs7BgHRoicJ_W_tNL8D0 (plaintext) in sankislayer/bot.py (+2 more) OBFUSCATION - Python Exec with Encoded Content in sankislayer/bot.py: "exec(base64.b64decode" - Decoded Base64 Content in sankislayer/bot.py - Base64 Encoded Payload in sankislayer/bot.py: ""IyEvdXNyL2Jpbi9lbnYgcHl0aG9uMwppbXBvcnQgYXN5bmNpbwppbXBvcnQganNvbgppbXBvcnQgb3M..." - Deobfuscation Failed in sankislayer/bot.py - recovered 9 urls, 10 domains, 1 paths from decoded/deobfuscated content ADDITIONAL FINDINGS - Base64 Decoded Eval in sankislayer/bot.py: "exec(base64.b64decode" - The entrypoint (`sankislayer/bot.py`) hardcodes 10 live Telegram bot tokens (e.g. `8670917633:AAHyYOvwq2J7KwP3m8UkG9jIWjY9V1suSLU`) and an OWNER_ID (`8756749479`), then uses `exec(base64.b64decode(PAYLOAD))` to load the full bot logic at runtime. The decoded payload implements coordinated spam loops (`/hinokamgi`, `/retsujitsu`, `/spam`) that use all 10 bots to flood Telegram groups at sub-10ms intervals, plus commands to promote bots to admin (`/promote`, `/hommie`), and OSINT lookups via attacker-controlled Workers.dev domains and `ft-osint-api.duckdns.org/api/numleak?key=freetill1` which leaks IMEI, MAC address, tower location, and identity data for Indian mobile numbers. The obfuscation layer (base64 exec) hides the full attack surface from static inspection. PAYLOAD FILES sankislayer/bot.py INDICATORS (IOCs) - domains: slayer.com, ig-adv.noobgamingv40.workers.dev, sc-avrg.noobgamingv40.workers.dev - emails: sanki@slayer.com - urls: https://ig-adv.noobgamingv40.workers.dev/info?username={username}, https://sc-avrg.noobgamingv40.workers.dev/info?user={username}, https://www.snapchat.com/add/{uname}, https://gh-avrg.noobgamingv40.workers.dev/info?user={username}, https://fb-adv.noobgamingv40.workers.dev/info?page={encoded_page} (+4 more) - paths: /usr/bin/env - payloadFileHash: 71f8f628b2cd8bcbf8e09cfd317bb5418499b7bec8fc3c019debcec1e457592d

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownsankislayerall (affected)

References

advisory
vendor

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›