{"id":"MAL-2026-17476","summary":"Malicious code in css-anchor-pos-fallback (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bd0a6c8e1448ffd9abb3732872ea3d49280a422d49524aaa57d0b89a73812f05)\nThe package advertises itself as a CSS anchor-position polyfill but on require executes an IIFE in thunderboltRegistry.js that runs `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and reads `/etc/hosts`, then POSTs the collected output along with hostname, platform, and Node version via fetch to the hardcoded external endpoint http://dxpoc.gt.tc/callback.php/. The module also exports keys named after Wix thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, etc.) with a bundled manifest referencing a parastorage.com unpkg URL, a shape consistent with dependency-confusion targeting of an internal Wix build pipeline. The advertised polyfill purpose is unrelated to shell execution, host reconnaissance, or outbound beaconing.\n","modified":"2026-10-04T23:30:06.640038101Z","published":"2026-10-04T23:13:37Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-04T23:16:30.194047624Z","modified_time":"2026-10-04T23:13:37Z","sha256":"bd0a6c8e1448ffd9abb3732872ea3d49280a422d49524aaa57d0b89a73812f05","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020882"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-anchor-pos-fallback/v/1.0.0"}],"affected":[{"package":{"name":"css-anchor-pos-fallback","ecosystem":"npm","purl":"pkg:npm/css-anchor-pos-fallback"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"css-anchor-pos-fallback-1.0.0.tgz","hashes":{"sha512_sri":"sha512-So/Lb4vSsrichmCat3kQSUgOXWLxqNzxC8BGSXIrLBGjzmuFNfyNyUtha/KAXVO9CPabz5egcGQT/7iSzjHLYQ==","sha1":"36551a24f198a0d6b93ed4fde353c98f43ffa06e"}}],"evidence_files":[{"tlsh":"697144a5b99df02165c33438cb7f4049b4bbc6672d6caee0744999b01f7985c01be6f4","path":"thunderboltRegistry.js","sha256":"b5389ce14f205c3930883356fdb46e32a129e17e008c100eae468409b3afaa4e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-anchor-pos-fallback/MAL-2026-17476.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}