npm · Malicious package advisory
Malwarecss-starting-style-polyfill
GHSA-64fj-vj54-m8r3
Malicious code in css-starting-style-polyfill (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (713c302594ab7c41e8034ca95478045afafba98e223ea62def160f080cb879cd) thunderboltRegistry.js runs an IIFE on module load that executes host reconnaissance commands via child_process.execSync (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) and transmits the collected output together with hostname, platform, and pid to a hardcoded external URL https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f via fetch. The package exports factories under names matching Wix internal registry modules (thunderboltRegistry, corvidRegistry, siteAssetsRegistry, editorRegistry, documentManagementRegistry) and ships a manifest referencing parastorage.com URLs, so any environment loading it as a drop-in Wix thunderbolt registry triggers the exfiltration payload on require(). The declared CSS @starting-style polyfill purpose has no relationship to the shipped behavior. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-starting-style-polyfill/MAL-2026-17488.json)) **References:** - https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-starting-style-polyfill/MAL-2026-17488.json - https://www.npmjs.com/package/css-starting-style-polyfill/v/1.0.0 - https://github.com/advisories/GHSA-64fj-vj54-m8r3
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.