{"id":"MAL-2026-17557","summary":"Malicious code in css-svqggc-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6b23cf39720388bcf9f26621bd52e256e18a011bf3b6821b7d9f5f60115b9663)\nPackage masquerades as a CSS polyfill while impersonating internal Wix Thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and other namespace stubs), with a shipped registry-manifest pointing those names at parastorage.com URLs under this package's own name — a dependency-confusion shape. thunderboltRegistry.js runs an IIFE on require that purges its own entries from require.cache so each require re-runs the payload, obtains child_process via multiple fallbacks (including constructing a fresh Module instance to bypass sandboxed require stubs), and executes reconnaissance commands (id, whoami, uname -a, ifconfig/ip addr, /etc/hosts) via execSync. The command output plus host beacon fields (node version, platform, pid, hostname, site) are sent over cleartext HTTP via fetch GET to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The Proxy-based stub exports ensure the import appears to succeed silently after exfiltration.\n","modified":"2026-10-05T04:15:05.704060384Z","published":"2026-10-05T03:37:03Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-05T03:57:39.532422737Z","modified_time":"2026-10-05T03:37:03Z","sha256":"6b23cf39720388bcf9f26621bd52e256e18a011bf3b6821b7d9f5f60115b9663","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021023"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-svqggc-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-svqggc-polyfill","ecosystem":"npm","purl":"pkg:npm/css-svqggc-polyfill"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-svqggc-polyfill/MAL-2026-17557.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928","tlsh":"e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8","path":"thunderboltRegistry.js"},{"path":"registry-manifest.min.json","sha256":"5d173e4ca9713636b5060832d6c8b8299136ad3115b7affcd0b7b88ddefec879","tlsh":"2301a5dd0c0a41fa1bc05acf4402fa0af7038dc60cedd672952141a078245f102febbb"}],"package_integrity":[{"filename":"css-svqggc-polyfill-1.0.0.tgz","hashes":{"sha1":"87eb3d48163b2973abfc3731895cef65d40cdeb4","sha512_sri":"sha512-zGStGUofphvCP3Ki3dp//PLu48U+P2QokbHMXFf5GGiNKvVAmnGYTDOxOvFKpTSs4j3mKrsz5avoHdRW37UZzw=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}