Logo
npm

css-kfvwax-polyfill@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC

Malicious

OSV ID

MAL-2026-17575

Ecosystem

npm

Summary

On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (id, whoami, uname -a), network interface listings (ifconfig/ip addr), and the contents of /etc/hosts, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure.

Source: amazon-inspector (2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.