VDB

GCVE-110-OSM-2026-13321

GCVE-110-OSM-2026-13321
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published October 4, 2026
The package is published as css-reading-flow-polyfill but ships thunderboltRegistry.js, which impersonates internal Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) by exporting all of those names from a single payload file. On require, an IIFE in thunderboltRegistry.js uses child_process.execSync to run id, whoami, uname, ifconfig/ip-addr and read /etc/hosts, then fetches http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP with the command output, hostname, Node version, platform and pid appended as query parameters. The module also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry' so the recon-and-exfil IIFE re-runs on every require rather than being cached. index.js is an empty decoy; the stated CSS polyfill purpose is a cover story and the package has no implementation of that functionality. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(site)).catch(function(){}); } catch(e" - System Information Collection in thunderboltRegistry.js: "process.platform" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Very New NPM Publisher Account - Publisher Has Other Malicious Packages PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncss-reading-flow-polyfillall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›