VDB

GCVE-110-OSM-2026-13284

GCVE-110-OSM-2026-13284
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 5, 2026
On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (`id`, `whoami`, `uname -a`), network interface listings (`ifconfig`/`ip addr`), and the contents of `/etc/hosts`, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (oast, custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in thunderboltRegistry.js: "oastify.com" - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e" - System Information Collection in thunderboltRegistry.js: "process.platform" - Suspicious Domain in thunderboltRegistry.js: "oastify.com" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncss-kfvwax-polyfillall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›