VYPR

npm · Malicious package advisory

Malware

css-interop-observer-polyfill

GHSA-h3hx-44p9-q47q

Malicious code in css-interop-observer-polyfill (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (089bdc1dd6bdf0216bb911888e81ce97dc171bdef2588fd5de0aadb4a64fbb2b)
On module load, thunderboltRegistry.js executes an IIFE that runs id, whoami, uname, ifconfig/ip addr via child_process.execSync and reads /etc/hosts, then sends each result together with hostname, node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/[token] via fetch over plain HTTP. The package presents itself as a stub exporting proxies for Wix thunderbolt internal registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), consistent with dependency-confusion targeting of those internal module names while the load-time code performs the host reconnaissance and exfiltration.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-interop-observer-polyfill/MAL-2026-17480.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-interop-observer-polyfill/MAL-2026-17480.json
- https://www.npmjs.com/package/css-interop-observer-polyfill/v/1.0.0
- https://github.com/advisories/GHSA-h3hx-44p9-q47q

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.