VDB

GCVE-110-OSM-2026-13298

GCVE-110-OSM-2026-13298
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 5, 2026
The package impersonates Wix thunderbolt internal registry modules (exporting `thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, etc. and shipping a `registry-manifest.min.json` referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e" - System Information Collection in thunderboltRegistry.js: "process.platform" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Brand New Package - Very New NPM Publisher Account PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncss-nbanqq-polyfillall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›