css-ikomdq-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17553
Ecosystem
npm
Summary
The package presents itself as a CSS polyfill but ships thunderboltRegistry.js, which on require() executes a top-level IIFE that runs id, whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts via child_process.execSync, then posts the command outputs together with hostname, node version, platform, and pid to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/ using fetch. The module also deletes its own entries from require.cache so the payload re-runs on each require() rather than being memoized. The package name and the thunderbolt/editor/corvid Proxy facade impersonate Wix parastorage registry modules to encourage accidental installation.
Source: amazon-inspector (255cceca3ca8631c9b225745c5b64a71fd6c09b60fa3ad95b419fccb66f035f2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.