VDB
GCVE-110-OSM-2026-13092
GCVE-110-OSM-2026-13092
Advisory PublishedCVSS 5.4/10
thunderboltRegistry.js executes whoami/uname/hostname//etc/hosts/ifconfig/id via execSync (lines 14, 21-45) and exfiltrates results via HTTP POST and DNS-subdomain beacons to an interactsh/oast.live C2 host (lines 4, 9, 22-35, 47-51). Disguised with benign Proxy stubs in a viewport-calc package; clear host recon/exfiltration malware.
## Static analysis (vigil)
Verdict `BLOCK`, score 36/100. Critical/high findings:
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/thunderboltRegistry.js:4`
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/thunderboltRegistry.js:38`
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/thunderboltRegistry.js:57`
- [critical] SC-026 Exfiltration/C2 infrastructure — `package/thunderboltRegistry.js:57`
- [high] SC-059 Interactsh/OAST callback domain — `package/thunderboltRegistry.js:4`
- [high] SC-059 Interactsh/OAST callback domain — `package/thunderboltRegistry.js:57`
- [high] SC-059 Interactsh/OAST callback domain — `package/thunderboltRegistry.js:57`
## Package metadata
- Publisher: unknown
- Published: 2026-10-03T00:25:52.318Z
- Install hooks: none found
- SHA-256 (tarball): `457a25fdcc6be709378fec09d94e417c303c06f9875ca16abccd78171b80e4ec`
## IOCs (defanged)
- davdpb8lhot13kgmnhp0863x9g83mpswq[.]oast[.]live
- hxxps://poc12-err
- hxxps://poc12-err[.]davdpb8lhot13kgmnhp0863x9g83mpswq[.]oast[.]live/err
- oast[.]live
- poc12-err[.]davdpb8lhot13kgmnhp0863x9g83mpswq[.]oast[.]live
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tiny-viewport-unit-calc | 1.0.0 (affected) | — |
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.