VDB

GCVE-110-OSM-2026-13317

GCVE-110-OSM-2026-13317
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 4, 2026
The package advertises itself as a CSS field-sizing polyfill but ships thunderboltRegistry.js, which runs an IIFE at module load time. The IIFE shells out via child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, then transmits the collected output together with hostname, Node version, platform, and pid as query-string parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The module also exports proxied stubs for Wix-internal names (`thunderboltRegistry`, `siteAssetsRegistry`, `documentManagementRegistry`, `editorRegistry`, `corvidRegistry`) and ships a `registry-manifest.min.json` pointing at `static.parastorage.com`, indicating a dependency-confusion impersonation of Wix internal packages so that an internal resolver pulling this public name will trigger the beacon. The reconnaissance behavior is unrelated to the declared CSS polyfill purpose and fires on any `require()` of the package. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e" - System Information Collection in thunderboltRegistry.js: "process.platform" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Very New NPM Publisher Account - Publisher Has Other Malicious Packages PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncss-field-sizing-polyfillall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›