{"id":"MAL-2026-17551","summary":"Malicious code in css-gvqmfn-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ffb3f332a818748252e49dcf21ffb6949c531afd401ee697cc08ba00a067ae30)\ncss-gvqmfn-polyfill mimics Wix internal @wix/thunderbolt-* CSS polyfill naming and ships a Proxy-based cover stub that re-exports registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) as no-op functions to appear functional. On require of thunderboltRegistry.js, an IIFE unconditionally executes `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts` via child_process, collects os.hostname, Node version, platform, and pid, and sends the output together with an `rce-poc` beacon to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP. The accompanying registry-manifest.min.json points sibling registries to parastorage.com URLs that do not host this file, consistent with a dependency-confusion lure targeting Wix build environments.\n","modified":"2026-10-05T04:15:05.203167504Z","published":"2026-10-05T03:36:27Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-05T03:36:27Z","sha256":"ffb3f332a818748252e49dcf21ffb6949c531afd401ee697cc08ba00a067ae30","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021019","import_time":"2026-10-05T03:57:39.185383499Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-gvqmfn-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-gvqmfn-polyfill","ecosystem":"npm","purl":"pkg:npm/css-gvqmfn-polyfill"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"css-gvqmfn-polyfill-1.0.0.tgz","hashes":{"sha1":"30f2ab1a20f691f72c8fca3449889030e47c80f4","sha512_sri":"sha512-gEh2j/WJZyUNAlzNFfSfSFxgB/8V5axZdaHpHnUAK+4vT6RoQDWCxfTyN9uBXJG4vTt6sL5ae6DiE254G5ViXA=="}}],"evidence_files":[{"tlsh":"e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8","path":"thunderboltRegistry.js","sha256":"a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-gvqmfn-polyfill/MAL-2026-17551.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}