npm · Malicious package advisory
Malwarecss-kfvwax-polyfill
GHSA-c9cg-4hcw-x27p
Malicious code in css-kfvwax-polyfill (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df) On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (`id`, `whoami`, `uname -a`), network interface listings (`ifconfig`/`ip addr`), and the contents of `/etc/hosts`, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json - https://www.npmjs.com/package/css-kfvwax-polyfill/v/1.0.0 - https://github.com/advisories/GHSA-c9cg-4hcw-x27p
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.