css-nbanqq-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17555
Ecosystem
npm
Summary
The package impersonates Wix thunderbolt internal registry modules (exporting thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc. and shipping a registry-manifest.min.json referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run id, whoami, uname -a, ifconfig/ip addr, and cat /etc/hosts, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.
Source: amazon-inspector (7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.