VDB
GCVE-110-OSM-2026-13317
GCVE-110-OSM-2026-13317
Advisory PublishedCVSS 8.8/10
The package advertises itself as a CSS field-sizing polyfill but ships thunderboltRegistry.js, which runs an IIFE at module load time. The IIFE shells out via child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, then transmits the collected output together with hostname, Node version, platform, and pid as query-string parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The module also exports proxied stubs for Wix-internal names (`thunderboltRegistry`, `siteAssetsRegistry`, `documentManagementRegistry`, `editorRegistry`, `corvidRegistry`) and ships a `registry-manifest.min.json` pointing at `static.parastorage.com`, indicating a dependency-confusion impersonation of Wix internal packages so that an internal resolver pulling this public name will trigger the beacon. The reconnaissance behavior is unrelated to the declared CSS polyfill purpose and fires on any `require()` of the package.
ENTRY
index.js (main: index.js)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e"
- System Information Collection in thunderboltRegistry.js: "process.platform"
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
- Very New NPM Publisher Account
- Publisher Has Other Malicious Packages
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-field-sizing-polyfill | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.