VDB
GCVE-110-OSM-2026-13312
GCVE-110-OSM-2026-13312
Advisory PublishedCVSS 8.8/10
The package is advertised as a focus-trap utility but thunderboltRegistry.js runs an IIFE at require time that uses child_process.execSync to run whoami, id, pwd, ifconfig / ip addr, hostname, and to read /etc/hosts, then sends each command's output as query parameters to http://dxpoc.gt.tc/callback.php via fetch. A separate beacon containing Node version, platform, and pid is also posted to the same endpoint. The package additionally impersonates Wix 'thunderbolt' internal registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry) and references static.parastorage.com manifest URLs, matching a dependency-confusion lure aimed at Wix build environments. Installing or importing this package causes the installer host's identity, network configuration, and /etc/hosts contents to be sent to an attacker-controlled host.
ENTRY
index.js (main: index.js)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(whoami"
- System Information Collection in thunderboltRegistry.js: "process.platform"
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
- Very New NPM Publisher Account
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tiny-dom-focus-trap | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.