VDB

GCVE-110-OSM-2026-13270

GCVE-110-OSM-2026-13270
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 6, 2026
The package self-identifies as a Wix AppSec dependency-confusion reproduction test (ticket TB-16251/ASST-56470), and the payload marker 'tb16251a' in registry.js and the IOC domain 'static.parastorage.com' (a legitimate Wix CDN) are internally consistent with that claim. However, the publisher 'naorya' already has one confirmed malicious package (css-eqxcdx-polyfill, medium severity), and the remaining css-[random]-polyfill packages pattern looks like a dependency-confusion campaign rather than a single isolated test. The registry.js file demonstrably collects and serializes hostname, PID, platform, and arch — real exfiltration behavior regardless of stated intent — and the destination endpoint is not visible in the available evidence. The combination of actual data harvesting code, a very new account, a prior malicious package, and eight look-alike polyfill packages makes the 'authorized internal test' framing insufficient to dismiss without corroboration from Wix. ADDITIONAL FINDINGS - Shell Command Execution in registry.js: "require("child_process")" - Platform Detection with Data Collection in registry.js: "JSON.stringify({m:"tb16251a",c:"hostname",o:out,e:err, pid:(p?p.pid:0),host:pod,..." - Very New NPM Publisher Account - Publisher Has Other Malicious Packages PAYLOAD FILES registry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknown@naorya/registry-override-reproall (affected)—

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›