VYPR

npm · Malicious package advisory

Malware

css-nrmgzn-polyfill

GHSA-6qc5-m3jm-2rg5

Malicious code in css-nrmgzn-polyfill (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (4522148c469356aa7799c831ce547d2ae612ac40621e5110ad5d5125bf2f2684)
The package presents itself as a CSS polyfill but on require() of thunderboltRegistry.js runs an IIFE that invokes child_process.execSync for id, whoami, uname, ifconfig, and cat /etc/hosts, and sends the command output together with os.hostname(), node version, platform and pid to a hardcoded Burp Collaborator subdomain at https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The package also exports modules named after internal Wix thunderbolt registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, documentManagementRegistry) and ships a manifest referencing static.parastorage.com paths for css-nrmgzn-polyfill, consistent with a dependency-confusion lure positioned to resolve in place of a private internal module in a Wix build or CI environment. Loading the package yields host reconnaissance exfiltration to an attacker-controlled OAST domain, with no polyfill functionality actually implemented.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-nrmgzn-polyfill/MAL-2026-17576.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-nrmgzn-polyfill/MAL-2026-17576.json
- https://www.npmjs.com/package/css-nrmgzn-polyfill/v/1.0.0
- https://github.com/advisories/GHSA-6qc5-m3jm-2rg5

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.