npm · Malicious package advisory
Malwarecss-light-dark-polyfill
GHSA-p6p9-mjx4-2fgf
Malicious code in css-light-dark-polyfill (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (856c154d7855924568c88181f172f46e84aac202bd6cb29974eb2ffaa3ec3ea7) The package presents itself as a trivial CSS polyfill (index.js exports an empty object) but ships thunderboltRegistry.js, which on load runs a self-invoking IIFE that collects host identifiers (os.hostname, node version, platform, pid) and the output of local shell commands (id, whoami, uname -a, ifconfig/ip addr, /etc/hosts via child_process.execSync) and POSTs each result via fetch() to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/. The payload self-labels as 'beacon=rce-poc'. The package also exports factories under the names of internal Wix Thunderbolt build registries (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, etc.), and a bundled registry-manifest.min.json maps those names to parastorage.com URLs — a dependency-confusion shape targeting Wix-like build systems that resolve these internal registry module names. Installing or loading this package causes host reconnaissance data to be exfiltrated to an attacker-controlled domain unrelated to any CSS polyfill functionality. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-light-dark-polyfill/MAL-2026-17481.json)) **References:** - https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-light-dark-polyfill/MAL-2026-17481.json - https://www.npmjs.com/package/css-light-dark-polyfill/v/1.0.0 - https://github.com/advisories/GHSA-p6p9-mjx4-2fgf
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.