{"id":"MAL-2026-17556","summary":"Malicious code in css-ogojwh-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aff543635c832e0563229f42fcc7673c835f2ba5a9ae41d680aa572cfba49765)\ncss-ogojwh-polyfill@1.0.0 presents itself as a CSS polyfill but ships thunderboltRegistry.js which, on require, runs an IIFE that executes shell commands via child_process.execSync (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) and POSTs their output along with hostname, Node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f, with a beacon label of `rce-poc`. The module also exports no-op Proxy stubs under module names matching Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, editorRegistry), consistent with a dependency-confusion / typosquat shim whose only real behavior is the recon-and-exfil payload executed at import time.\n","modified":"2026-10-05T04:15:05.068128212Z","published":"2026-10-05T03:36:05Z","database_specific":{"malicious-packages-origins":[{"sha256":"aff543635c832e0563229f42fcc7673c835f2ba5a9ae41d680aa572cfba49765","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021017","import_time":"2026-10-05T03:57:39.04950358Z","modified_time":"2026-10-05T03:36:05Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-ogojwh-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-ogojwh-polyfill","ecosystem":"npm","purl":"pkg:npm/css-ogojwh-polyfill"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8","path":"thunderboltRegistry.js","sha256":"a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-9J0X+2VJAshTo2Mvv1Chb1YdFp6lj3sxQ2nkMQc6+43W0h+lajwG99tGqcu574Rp63sldaWqmqKxaoqRmc8y1g==","sha1":"05e1e1171265d9abec7ed2e5eb8e77f251e04fc3"},"filename":"css-ogojwh-polyfill-1.0.0.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-ogojwh-polyfill/MAL-2026-17556.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}