{"id":"MAL-2026-17555","summary":"Malicious code in css-nbanqq-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f)\nThe package impersonates Wix thunderbolt internal registry modules (exporting `thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, etc. and shipping a `registry-manifest.min.json` referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.\n","modified":"2026-10-05T04:15:06.608711356Z","published":"2026-10-05T03:35:45Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-05T03:35:45Z","sha256":"7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021015","import_time":"2026-10-05T03:57:38.808911914Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-nbanqq-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-nbanqq-polyfill","ecosystem":"npm","purl":"pkg:npm/css-nbanqq-polyfill"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"css-nbanqq-polyfill-1.0.0.tgz","hashes":{"sha512_sri":"sha512-waeHo5RpZ3D01CpUL8ZvjNwC5UUJetTCLMWk7Um5lJViHp0RpW/fQHRF73ZjkO3uw7gaaIP2fTNPlGj45Ovdlg==","sha1":"173ab1b2e46712e9da9269c952e43aca1d2763d6"}}],"evidence_files":[{"tlsh":"e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8","path":"thunderboltRegistry.js","sha256":"a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-nbanqq-polyfill/MAL-2026-17555.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}