{"id":"MAL-2026-17550","summary":"Malicious code in css-dwsawd-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1c370cda09695e44d06a44bc14d14817edadc047e4dad0314edcfc752be796e9)\nThe package name mimics a Wix thunderbolt polyfill and ships a registry-manifest.min.json that aliases legitimate @wix thunderbolt registry module names to thunderboltRegistry.js. On require, thunderboltRegistry.js runs an IIFE that uses child_process.execSync to execute shell reconnaissance (id, whoami, uname -a, ifconfig/ip addr, /etc/hosts) and fetches http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f with the command outputs plus hostname, pid, platform, node version, and a site identifier as query parameters, tagged 'rce-poc'. A fallback path constructs a fresh Module instance to re-resolve child_process if the require cache is stubbed, ensuring execution. The destination is plain HTTP to an unrelated external host and is not caller-configurable.\n","modified":"2026-10-05T04:15:06.620461320Z","published":"2026-10-05T03:35:36Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-05T03:35:36Z","sha256":"1c370cda09695e44d06a44bc14d14817edadc047e4dad0314edcfc752be796e9","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021014","import_time":"2026-10-05T03:57:38.728986068Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-dwsawd-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-dwsawd-polyfill","ecosystem":"npm","purl":"pkg:npm/css-dwsawd-polyfill"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928","tlsh":"e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8"}],"package_integrity":[{"hashes":{"sha1":"ef15ad08c629a871720ac3361d4a8cb32af8a865","sha512_sri":"sha512-aD51izXwj5rI+FHut4JDVOSRAnc6akSkrOPliR6OjNLbM3UMS8iuM829TvknAlt8CGUhf+ttjzYb+bJAGLIwpw=="},"filename":"css-dwsawd-polyfill-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-dwsawd-polyfill/MAL-2026-17550.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}