VYPR

npm · Malicious package advisory

Malware

css-anchor-pos-fallback

MAL-2026-17476

Malicious code in css-anchor-pos-fallback (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bd0a6c8e1448ffd9abb3732872ea3d49280a422d49524aaa57d0b89a73812f05)
The package advertises itself as a CSS anchor-position polyfill but on require executes an IIFE in thunderboltRegistry.js that runs `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and reads `/etc/hosts`, then POSTs the collected output along with hostname, platform, and Node version via fetch to the hardcoded external endpoint http://dxpoc.gt.tc/callback.php/. The module also exports keys named after Wix thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, etc.) with a bundled manifest referencing a parastorage.com unpkg URL, a shape consistent with dependency-confusion targeting of an internal Wix build pipeline. The advertised polyfill purpose is unrelated to shell execution, host reconnaissance, or outbound beaconing.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.