{"id":"MAL-2026-17575","summary":"Malicious code in css-kfvwax-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df)\nOn require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (`id`, `whoami`, `uname -a`), network interface listings (`ifconfig`/`ip addr`), and the contents of `/etc/hosts`, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure.\n","modified":"2026-10-05T16:31:36.999258223Z","published":"2026-10-05T16:14:25Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021077","import_time":"2026-10-05T16:22:56.858031177Z","modified_time":"2026-10-05T16:14:25Z","sha256":"2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-kfvwax-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-kfvwax-polyfill","ecosystem":"npm","purl":"pkg:npm/css-kfvwax-polyfill"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"css-kfvwax-polyfill-1.0.0.tgz","hashes":{"sha1":"11eafd4ac50d3d8cb64cda2a17520f203c5624cc","sha512_sri":"sha512-lURemH1bGmfUVRgvkECW9FjDD3pPZhb7pHailTz4l15DmcEz+R8qBaKJ+cZSSs5dEgplBhX+apDEsyBLGdqDsg=="}}],"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"eea1ba8ba61d690d808a52ef7fec1a4115e5f322572c5c6241a6dfbcc3223abe","tlsh":"b47153a5b99df02166c33438cb7f5049b4bbc6672c6caee0740899b02f7985c01be6f5"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}