VDB
GCVE-110-OSM-2026-13298
GCVE-110-OSM-2026-13298
Advisory PublishedCVSS 8.8/10
The package impersonates Wix thunderbolt internal registry modules (exporting `thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, etc. and shipping a `registry-manifest.min.json` referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.
ENTRY
index.js (main: index.js)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e"
- System Information Collection in thunderboltRegistry.js: "process.platform"
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
- Brand New Package
- Very New NPM Publisher Account
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-nbanqq-polyfill | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.