VYPR

npm · Malicious package advisory

Malware

css-anchor-pos-fallback

GHSA-4ppq-v2jm-24mc

Malicious code in css-anchor-pos-fallback (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (bd0a6c8e1448ffd9abb3732872ea3d49280a422d49524aaa57d0b89a73812f05)
The package advertises itself as a CSS anchor-position polyfill but on require executes an IIFE in thunderboltRegistry.js that runs `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and reads `/etc/hosts`, then POSTs the collected output along with hostname, platform, and Node version via fetch to the hardcoded external endpoint http://dxpoc.gt.tc/callback.php/. The module also exports keys named after Wix thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, etc.) with a bundled manifest referencing a parastorage.com unpkg URL, a shape consistent with dependency-confusion targeting of an internal Wix build pipeline. The advertised polyfill purpose is unrelated to shell execution, host reconnaissance, or outbound beaconing.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-anchor-pos-fallback/MAL-2026-17476.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-anchor-pos-fallback/MAL-2026-17476.json
- https://www.npmjs.com/package/css-anchor-pos-fallback/v/1.0.0
- https://github.com/advisories/GHSA-4ppq-v2jm-24mc

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.