{"id":"MAL-2026-17573","summary":"Malicious code in css-eqxcdx-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a93fe0298f7671177e324947b2bf89ec3729b203621f7ca67aa8cd10439306a2)\nThe package presents itself as a polyfill exporting Wix thunderbolt-style registry stubs (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, etc.), but thunderboltRegistry.js runs an IIFE on module load that performs two installer-side attacks. First, it executes `id`, `whoami`, `env`, and `ifconfig`/`ip addr` via child_process.execSync, collects the OS hostname, and POSTs the output together with a wholesale dump of process environment variables via fetch() to the hardcoded Burp Collaborator OAST host https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/, including a tagged `cmd=env` beacon. Environment variables on developer and CI hosts routinely contain cloud, registry, and CI credentials. Second, it runs `curl -L https://appsecc.com/py | python3` via execSync, fetching and executing an arbitrary remote Python payload on the installer's machine, with a self-labeled `cmd=reverse-shell` beacon sent to the same OAST host. The registry-API facade and the Wix-adjacent naming are cover for the reconnaissance and remote code execution in the same file; the package has no legitimate functionality.\n","modified":"2026-10-05T16:31:38.282208005Z","published":"2026-10-05T16:14:36Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-021078","import_time":"2026-10-05T16:22:56.912573368Z","modified_time":"2026-10-05T16:14:36Z","sha256":"a93fe0298f7671177e324947b2bf89ec3729b203621f7ca67aa8cd10439306a2","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-eqxcdx-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-eqxcdx-polyfill","ecosystem":"npm","purl":"pkg:npm/css-eqxcdx-polyfill"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"e07131b5b99df02166c33438db7f5049b4bb86672c6caee0740899b01f7585c01ba6f4","path":"thunderboltRegistry.js","sha256":"098fac4f87d662808d1fcb744c79416ac42dd1ae997a1f96a998f2f3b46ce699"}],"package_integrity":[{"filename":"css-eqxcdx-polyfill-1.0.0.tgz","hashes":{"sha1":"7557c9d44b83fa297b2e679935c315e8c63186c5","sha512_sri":"sha512-K2Cyx29csVIzcdLgoftJ1PQfZBb8NB8x28Hl8TRWDN+4ZLcgL7uFBSPd4rIgt9MXy/fWsOWXMSWXX8QPTeUJTg=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-eqxcdx-polyfill/MAL-2026-17573.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}