css-hgwctv-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17552
Ecosystem
npm
Summary
On require, thunderboltRegistry.js runs an immediately-invoked function that uses child_process.execSync to collect host identity and network reconnaissance from the installer's machine (id, whoami, uname -a, ifconfig/ip addr, and /etc/hosts), plus hostname, Node.js version, platform and pid, and transmits each result via fetch to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The package also exports Proxy stubs named thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry and ships a registry-manifest.min.json referencing parastorage.com, mimicking internal Wix thunderbolt build modules so the module auto-loads inside a Wix build and executes the reconnaissance payload. A CSS polyfill has no functional reason to execute shell commands, read /etc/hosts, or contact an external host.
Source: amazon-inspector (ee1103a16c6f933686f07e8ce94068057f49e5cf2f0a6a9ccf01f2baeb7cfe95)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.