Logo
npm

css-nbanqq-polyfill@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17555

Ecosystem

npm

Summary

The package impersonates Wix thunderbolt internal registry modules (exporting thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc. and shipping a registry-manifest.min.json referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run id, whoami, uname -a, ifconfig/ip addr, and cat /etc/hosts, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.

Source: amazon-inspector (7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.