VDB

GCVE-110-OSM-2026-13316

GCVE-110-OSM-2026-13316
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 4, 2026
Package self-describes as a CSS env() shim but ships thunderboltRegistry.js, which runs an IIFE at module load that base64-decodes the strings 'child_process' and 'execSync', dynamically requires child_process, and shells out whoami, uname, cat /etc/hosts, ifconfig/ip addr, id, and hostname. The collected output is POSTed to a hardcoded webhook.site URL (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba) and beaconed to a subdomain of davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live for DNS exfiltration. All sensitive identifiers (module name, method name, commands, destination host, UUID path, OAST subdomain) are stored as base64 blobs or String.fromCharCode arrays and reconstructed at runtime to defeat static inspection. index.js is a stub; the module factory is re-exported under nine Wix-internal registry key names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and similar), and the shipped registry-manifest.min.json aliases numerous Wix thunderbolt *Registry.js URLs on parastorage.com to this package's thunderboltRegistry.js — a dependency-confusion lure targeting Wix's internal build so that any importer of those names triggers the exfiltration IIFE at require time. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(label) + "&o=" + encodeURIComponent(out.substring(0, 1800)))...." - Network Request in thunderboltRegistry.js: "fetch("https:" OBFUSCATION - Decoded Base64 Content in thunderboltRegistry.js ADDITIONAL FINDINGS - XOR-Encoded String Arrays in thunderboltRegistry.js: "var _u1 = [119,101,98,104,111,111,107,46,115,105,116,101]" - Very New NPM Publisher Account - Publisher Has Other Malicious Packages PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncss-env-function-shimall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›