VDB

GCVE-110-OSM-2026-13215

GCVE-110-OSM-2026-13215
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 5, 2026
a11y-tabindex-manager ships thunderboltRegistry.js, which executes an IIFE on module load that runs a series of local shell commands (cat /etc/hosts, whoami, id, pwd, ifconfig/ip addr, hostname, cat /etc/resolv.conf, uname -a, env | head -50) via child_process.execSync and POSTs each output over plain HTTP to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. A separate beacon labeled 'rce-poc-v3' sends Node.js version, platform, and PID to the same host. child_process is acquired both directly and via a fallback that instantiates a new Module (new module.constructor()) and copies module.paths — an evasion technique to bypass simple require('child_process') scans. The package name resembles a generic accessibility helper, but the shipped registry entry performs host identity, network configuration, user, and environment-variable harvesting with no legitimate purpose. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(etchosts.substring(0, 2000" - System Information Collection in thunderboltRegistry.js: "process.platform" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Very New NPM Publisher Account PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowna11y-tabindex-managerall (affected)—

References

advisory
vendor

Browse GCVE Records

3,142 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›