css-anchor-pos-fallback@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17476
Ecosystem
npm
Summary
The package advertises itself as a CSS anchor-position polyfill but on require executes an IIFE in thunderboltRegistry.js that runs id, whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts, then POSTs the collected output along with hostname, platform, and Node version via fetch to the hardcoded external endpoint http://dxpoc.gt.tc/callback.php/. The module also exports keys named after Wix thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, etc.) with a bundled manifest referencing a parastorage.com unpkg URL, a shape consistent with dependency-confusion targeting of an internal Wix build pipeline. The advertised polyfill purpose is unrelated to shell execution, host reconnaissance, or outbound beaconing.
Source: amazon-inspector (bd0a6c8e1448ffd9abb3732872ea3d49280a422d49524aaa57d0b89a73812f05)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.