{"id":"MAL-2026-17576","summary":"Malicious code in css-nrmgzn-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4522148c469356aa7799c831ce547d2ae612ac40621e5110ad5d5125bf2f2684)\nThe package presents itself as a CSS polyfill but on require() of thunderboltRegistry.js runs an IIFE that invokes child_process.execSync for id, whoami, uname, ifconfig, and cat /etc/hosts, and sends the command output together with os.hostname(), node version, platform and pid to a hardcoded Burp Collaborator subdomain at https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The package also exports modules named after internal Wix thunderbolt registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, documentManagementRegistry) and ships a manifest referencing static.parastorage.com paths for css-nrmgzn-polyfill, consistent with a dependency-confusion lure positioned to resolve in place of a private internal module in a Wix build or CI environment. Loading the package yields host reconnaissance exfiltration to an attacker-controlled OAST domain, with no polyfill functionality actually implemented.\n","modified":"2026-10-05T16:31:38.291898077Z","published":"2026-10-05T16:15:10Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-05T16:22:57.198924026Z","modified_time":"2026-10-05T16:15:10Z","sha256":"4522148c469356aa7799c831ce547d2ae612ac40621e5110ad5d5125bf2f2684","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021082"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-nrmgzn-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-nrmgzn-polyfill","ecosystem":"npm","purl":"pkg:npm/css-nrmgzn-polyfill"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"eea1ba8ba61d690d808a52ef7fec1a4115e5f322572c5c6241a6dfbcc3223abe","tlsh":"b47153a5b99df02166c33438cb7f5049b4bbc6672c6caee0740899b02f7985c01be6f5"}],"package_integrity":[{"filename":"css-nrmgzn-polyfill-1.0.0.tgz","hashes":{"sha1":"e672b68052edc0e4b805f50f161b117b0d5b17eb","sha512_sri":"sha512-KhcltUjoZ8S9Hug8iBW4VHTRycfAUbm4sVOT0aZ9zVBmX9EGxYbb0K4ER52nkhKlty5E3E+8VNNNEJNpP+Kjqg=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-nrmgzn-polyfill/MAL-2026-17576.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}