VDB
GCVE-110-OSM-2026-8867
GCVE-110-OSM-2026-8867
Advisory PublishedCVSS 5.4/10
This package presents as a Free Fire (Garena) account generator — a classic social-engineering lure used to distribute infostealers to users seeking game cheats. The presence of obfuscated binary-looking unicode escape sequences and a large hex-encoded payload in nero/main.py alongside os.system() shell execution is inconsistent with a legitimate automation tool and suggests hidden functionality. However, the only recovered IOCs are legitimate Garena API endpoints (100067.connect.garena.com, loginbp.ggblueshark.com, loginbp.common.ggbluefox.com), and no exfil destination (webhook, paste site, tunnel) was detected — leaving the attacker model unclear. The combination of a brand-new single-package account from an anonymous publisher, obfuscated content, and a 'free account generator' lure is a well-documented dropper pattern even if the payload hasn't been fully decoded. Manual analysis of nero/main.py is needed to determine whether the obfuscated content targets the installer's credentials or merely hides API interaction logic.
OBFUSCATION
- Base64 Encoded Payload in nero/main.py: ""3265653434383139653962343539383834353134313036376232383136323138373464306435643..."
- Unicode Escape Obfuscation in nero/main.py: "\xe0\x03\xa8\x81\x02\xe8\x03\xf6\xe5\x01\xf0\x03\xaf\x13\xf8\x03\x84\x07\x80\x04..."
ADDITIONAL FINDINGS
- Shell Command Execution in nero/main.py: "os.system("
PAYLOAD FILES
nero/main.py
INDICATORS (IOCs)
- urls: https://100067.connect.garena.com/api/v2/oauth/guest:register, https://100067.connect.garena.com/oauth/guest/token/grant, https://loginbp.ggblueshark.com/MajorRegister, https://loginbp.common.ggbluefox.com/MajorRegister, https://loginbp.ggblueshark.com/MajorLogin (+3 more)
- domains: 100067.connect.garena.com, loginbp.ggblueshark.com, loginbp.common.ggbluefox.com
- sha256Hashes: afcfbf13334be42036e4f742c80b956344bed760ac91b3aff9b607a610ab4390
- payloadFileHash: ebb68538989eb35b765a8ded8faafec9da1185d9342251e0625d8265820f1ddc
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | neroteam-v1 | 1.0.3 (affected) | — |
Aliases
Browse GCVE Records
77,041 records in the GCVE database · Updated August 7, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.