VDB
GCVE-110-OSM-2026-13396
GCVE-110-OSM-2026-13396
Advisory PublishedCVSS 5.4/10
The package advertises itself as a CSS overscroll-behavior utility but its shipped modules (thunderboltRegistry.js and sibling files named after Wix-internal registries such as siteAssetsRegistry, editorRegistry, corvidRegistry) run a self-executing IIFE at module load that performs host reconnaissance and bulk credential theft. The IIFE uses child_process.execSync and https.get/fetch to collect host identity (uname, hostname/id), file descriptors, /proc/self/mountinfo, network/DNS data, process environment variables matched by the pattern (KEY|TOKEN|SECRET|AUTH|...), and the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, posting each result to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The same load-time code probes container-escape primitives via unshare --user --mount with devtmpfs/cgroup/release_agent mounts and a perl memfd_create+exec sequence, and ships a registry-manifest.min.json that points at static.parastorage.com/unpkg/css-overscroll-contain@1.0.1/ so the package resolves inside Wix thunderbolt build infrastructure. The declared package purpose, the Wix-internal export names, the attacker endpoint, and the credential-grade data flow are all incompatible with a legitimate CSS utility.
ENTRY
index.js (main: index.js)
DESTINATION
- 1 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in thunderboltRegistry.js: "webhook.site"
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(tag) + "&d=" + encodeURIComponent(d) + "&t=" + Date.now()).ca..."
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
- Very New NPM Publisher Account
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | css-overscroll-contain | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.