VDB
GCVE-110-OSM-2026-13270
GCVE-110-OSM-2026-13270
Advisory PublishedCVSS 5.4/10
The package self-identifies as a Wix AppSec dependency-confusion reproduction test (ticket TB-16251/ASST-56470), and the payload marker 'tb16251a' in registry.js and the IOC domain 'static.parastorage.com' (a legitimate Wix CDN) are internally consistent with that claim. However, the publisher 'naorya' already has one confirmed malicious package (css-eqxcdx-polyfill, medium severity), and the remaining css-[random]-polyfill packages pattern looks like a dependency-confusion campaign rather than a single isolated test. The registry.js file demonstrably collects and serializes hostname, PID, platform, and arch — real exfiltration behavior regardless of stated intent — and the destination endpoint is not visible in the available evidence. The combination of actual data harvesting code, a very new account, a prior malicious package, and eight look-alike polyfill packages makes the 'authorized internal test' framing insufficient to dismiss without corroboration from Wix.
ADDITIONAL FINDINGS
- Shell Command Execution in registry.js: "require("child_process")"
- Platform Detection with Data Collection in registry.js: "JSON.stringify({m:"tb16251a",c:"hostname",o:out,e:err, pid:(p?p.pid:0),host:pod,..."
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
PAYLOAD FILES
registry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @naorya/registry-override-repro | all (affected) | — |
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.