VDB
GCVE-110-OSM-2026-13316
GCVE-110-OSM-2026-13316
Advisory PublishedCVSS 8.8/10
Package self-describes as a CSS env() shim but ships thunderboltRegistry.js, which runs an IIFE at module load that base64-decodes the strings 'child_process' and 'execSync', dynamically requires child_process, and shells out whoami, uname, cat /etc/hosts, ifconfig/ip addr, id, and hostname. The collected output is POSTed to a hardcoded webhook.site URL (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba) and beaconed to a subdomain of davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live for DNS exfiltration. All sensitive identifiers (module name, method name, commands, destination host, UUID path, OAST subdomain) are stored as base64 blobs or String.fromCharCode arrays and reconstructed at runtime to defeat static inspection. index.js is a stub; the module factory is re-exported under nine Wix-internal registry key names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and similar), and the shipped registry-manifest.min.json aliases numerous Wix thunderbolt *Registry.js URLs on parastorage.com to this package's thunderboltRegistry.js — a dependency-confusion lure targeting Wix's internal build so that any importer of those names triggers the exfiltration IIFE at require time.
ENTRY
index.js (main: index.js)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(label) + "&o=" + encodeURIComponent(out.substring(0, 1800)))...."
- Network Request in thunderboltRegistry.js: "fetch("https:"
OBFUSCATION
- Decoded Base64 Content in thunderboltRegistry.js
ADDITIONAL FINDINGS
- XOR-Encoded String Arrays in thunderboltRegistry.js: "var _u1 = [119,101,98,104,111,111,107,46,115,105,116,101]"
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-env-function-shim | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.