css-interop-observer-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17480
Ecosystem
npm
Summary
On module load, thunderboltRegistry.js executes an IIFE that runs id, whoami, uname, ifconfig/ip addr via child_process.execSync and reads /etc/hosts, then sends each result together with hostname, node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/[token] via fetch over plain HTTP. The package presents itself as a stub exporting proxies for Wix thunderbolt internal registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), consistent with dependency-confusion targeting of those internal module names while the load-time code performs the host reconnaissance and exfiltration.
Source: amazon-inspector (089bdc1dd6bdf0216bb911888e81ce97dc171bdef2588fd5de0aadb4a64fbb2b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.