npm · Malicious package advisory
Malwarecss-field-sizing-polyfill
GHSA-rmf7-f53x-p8v6
Malicious code in css-field-sizing-polyfill (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (549bb8820cb6a8a35853826d17b64df14c0561b83790192a33c5dc76dbad53b9) The package advertises itself as a CSS field-sizing polyfill but ships thunderboltRegistry.js, which runs an IIFE at module load time. The IIFE shells out via child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, then transmits the collected output together with hostname, Node version, platform, and pid as query-string parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The module also exports proxied stubs for Wix-internal names (`thunderboltRegistry`, `siteAssetsRegistry`, `documentManagementRegistry`, `editorRegistry`, `corvidRegistry`) and ships a `registry-manifest.min.json` pointing at `static.parastorage.com`, indicating a dependency-confusion impersonation of Wix internal packages so that an internal resolver pulling this public name will trigger the beacon. The reconnaissance behavior is unrelated to the declared CSS polyfill purpose and fires on any `require()` of the package. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-field-sizing-polyfill/MAL-2026-17478.json)) **References:** - https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-field-sizing-polyfill/MAL-2026-17478.json - https://www.npmjs.com/package/css-field-sizing-polyfill/v/1.0.0 - https://github.com/advisories/GHSA-rmf7-f53x-p8v6
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.