css-at-scope-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17547
Ecosystem
npm
Summary
Package is published under a CSS-polyfill name but ships thunderboltRegistry.js, which exports Wix internal registry module names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) so that a build resolving any of those names will load this file. On require(), an IIFE runs child_process.execSync to collect id, whoami, uname, ifconfig/ip addr, and the contents of /etc/hosts, plus a beacon containing node version, platform, pid, and hostname, and POSTs the output via fetch to the hardcoded HTTP endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The payload clears any require.cache entries referencing 'thunderboltRegistry' and acquires child_process through three fallbacks, including instantiating a new Module via module.constructor to bypass mocks or sandboxes. The declared CSS-polyfill purpose has no relation to this behavior; the shape is a dependency-confusion squat against internal Wix modules.
Source: amazon-inspector (c4d8d974b7fabf04fa662971cd8041fb76775bf5ed2902cbbffed0f881e2036d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.