css-field-sizing-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17478
Ecosystem
npm
Summary
The package advertises itself as a CSS field-sizing polyfill but ships thunderboltRegistry.js, which runs an IIFE at module load time. The IIFE shells out via child_process.execSync to run id, whoami, uname -a, ifconfig/ip addr, and cat /etc/hosts, then transmits the collected output together with hostname, Node version, platform, and pid as query-string parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The module also exports proxied stubs for Wix-internal names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com, indicating a dependency-confusion impersonation of Wix internal packages so that an internal resolver pulling this public name will trigger the beacon. The reconnaissance behavior is unrelated to the declared CSS polyfill purpose and fires on any require() of the package.
Source: amazon-inspector (549bb8820cb6a8a35853826d17b64df14c0561b83790192a33c5dc76dbad53b9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.