VDB

GCVE-110-OSM-2026-8867

GCVE-110-OSM-2026-8867
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 20, 2026
This package presents as a Free Fire (Garena) account generator — a classic social-engineering lure used to distribute infostealers to users seeking game cheats. The presence of obfuscated binary-looking unicode escape sequences and a large hex-encoded payload in nero/main.py alongside os.system() shell execution is inconsistent with a legitimate automation tool and suggests hidden functionality. However, the only recovered IOCs are legitimate Garena API endpoints (100067.connect.garena.com, loginbp.ggblueshark.com, loginbp.common.ggbluefox.com), and no exfil destination (webhook, paste site, tunnel) was detected — leaving the attacker model unclear. The combination of a brand-new single-package account from an anonymous publisher, obfuscated content, and a 'free account generator' lure is a well-documented dropper pattern even if the payload hasn't been fully decoded. Manual analysis of nero/main.py is needed to determine whether the obfuscated content targets the installer's credentials or merely hides API interaction logic. OBFUSCATION - Base64 Encoded Payload in nero/main.py: ""3265653434383139653962343539383834353134313036376232383136323138373464306435643..." - Unicode Escape Obfuscation in nero/main.py: "\xe0\x03\xa8\x81\x02\xe8\x03\xf6\xe5\x01\xf0\x03\xaf\x13\xf8\x03\x84\x07\x80\x04..." ADDITIONAL FINDINGS - Shell Command Execution in nero/main.py: "os.system(" PAYLOAD FILES nero/main.py INDICATORS (IOCs) - urls: https://100067.connect.garena.com/api/v2/oauth/guest:register, https://100067.connect.garena.com/oauth/guest/token/grant, https://loginbp.ggblueshark.com/MajorRegister, https://loginbp.common.ggbluefox.com/MajorRegister, https://loginbp.ggblueshark.com/MajorLogin (+3 more) - domains: 100067.connect.garena.com, loginbp.ggblueshark.com, loginbp.common.ggbluefox.com - sha256Hashes: afcfbf13334be42036e4f742c80b956344bed760ac91b3aff9b607a610ab4390 - payloadFileHash: ebb68538989eb35b765a8ded8faafec9da1185d9342251e0625d8265820f1ddc

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownneroteam-v11.0.3 (affected)

References

advisory
vendor

Browse GCVE Records

77,041 records in the GCVE database · Updated August 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›