{"id":"MAL-2026-17486","summary":"Malicious code in css-scroll-state-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cffa0affc34bac3fa24fcc7c67aae4d120066f4f856cb8b637bc04c6ca9d482c)\nThe package presents itself as a CSS polyfill but ships a payload file (thunderboltRegistry.js) that executes an IIFE at require time. The IIFE uses child_process to run host-identification commands (id, whoami, uname -a, ifconfig/ip addr, /etc/hosts, hostname) and collects Node version, platform, and PID, then sends the captured data via fetch to a hardcoded webhook.site collector at https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The main index.js is an empty stub; filenames mimic internal Wix Thunderbolt registry modules, consistent with a dependency-confusion squat targeting that namespace. A self-identifying 'beacon=poc15' tag is included in the request. The payload also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry', causing subsequent requires in the same process to re-execute the recon-and-exfiltration path rather than return a cached export, and exports a Proxy that answers arbitrary method accesses to blend in with the impersonated registry.\n","modified":"2026-10-04T23:30:04.669913596Z","published":"2026-10-04T23:15:41Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020895","import_time":"2026-10-04T23:16:30.95592812Z","modified_time":"2026-10-04T23:15:41Z","sha256":"cffa0affc34bac3fa24fcc7c67aae4d120066f4f856cb8b637bc04c6ca9d482c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-scroll-state-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-scroll-state-polyfill","ecosystem":"npm","purl":"pkg:npm/css-scroll-state-polyfill"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"0f60c0bf1fdb0b33fe163dfd84fa61885547141be10240bf513a3f9801d97d92","tlsh":"4e7122a5b99df02166c33438cb7f5049f4bbd6672c6caee0b40999b01f7985c01ba6f4"}],"package_integrity":[{"filename":"css-scroll-state-polyfill-1.0.0.tgz","hashes":{"sha1":"dbebb622ac294f78bc3d26d9b4fa4e9b6aab21b0","sha512_sri":"sha512-qFbxjMfDsXdkoaYHkbdWEDFuWFLdugfYyAVFLz2jRGlgMsekQaHMFBQ5YkmWlgLHLpiNcvVzAyYfjwOTSeJCbw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-scroll-state-polyfill/MAL-2026-17486.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}