VDB

GCVE-110-OSM-2026-13310

GCVE-110-OSM-2026-13310
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 5, 2026
Package name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes `id` and `uname -r` via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape. ENTRY index.js (main: index.js) DESTINATION - 3 exfil (reconstructed, custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in thunderboltRegistry.js: ".oast.live" - Network Request in thunderboltRegistry.js: "fetch("https:" OBFUSCATION - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in thunderboltRegistry.js: "https://noid.id.davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live/z" - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Very New NPM Publisher Account PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownrgx33-flex-layout-coreall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›