Logo
npm

css-ikomdq-polyfill@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17553

Ecosystem

npm

Summary

The package presents itself as a CSS polyfill but ships thunderboltRegistry.js, which on require() executes a top-level IIFE that runs id, whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts via child_process.execSync, then posts the command outputs together with hostname, node version, platform, and pid to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/ using fetch. The module also deletes its own entries from require.cache so the payload re-runs on each require() rather than being memoized. The package name and the thunderbolt/editor/corvid Proxy facade impersonate Wix parastorage registry modules to encourage accidental installation.

Source: amazon-inspector (255cceca3ca8631c9b225745c5b64a71fd6c09b60fa3ad95b419fccb66f035f2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.