Logo
npm

css-gvqmfn-polyfill@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17551

Ecosystem

npm

Summary

css-gvqmfn-polyfill mimics Wix internal @wix/thunderbolt-* CSS polyfill naming and ships a Proxy-based cover stub that re-exports registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) as no-op functions to appear functional. On require of thunderboltRegistry.js, an IIFE unconditionally executes id, whoami, uname -a, ifconfig/ip addr, and cat /etc/hosts via child_process, collects os.hostname, Node version, platform, and pid, and sends the output together with an rce-poc beacon to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP. The accompanying registry-manifest.min.json points sibling registries to parastorage.com URLs that do not host this file, consistent with a dependency-confusion lure targeting Wix build environments.

Source: amazon-inspector (ffb3f332a818748252e49dcf21ffb6949c531afd401ee697cc08ba00a067ae30)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.