VYPR

npm · Malicious package advisory

Malware

css-field-sizing-polyfill

MAL-2026-17478

Malicious code in css-field-sizing-polyfill (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (549bb8820cb6a8a35853826d17b64df14c0561b83790192a33c5dc76dbad53b9)
The package advertises itself as a CSS field-sizing polyfill but ships thunderboltRegistry.js, which runs an IIFE at module load time. The IIFE shells out via child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, then transmits the collected output together with hostname, Node version, platform, and pid as query-string parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The module also exports proxied stubs for Wix-internal names (`thunderboltRegistry`, `siteAssetsRegistry`, `documentManagementRegistry`, `editorRegistry`, `corvidRegistry`) and ships a `registry-manifest.min.json` pointing at `static.parastorage.com`, indicating a dependency-confusion impersonation of Wix internal packages so that an internal resolver pulling this public name will trigger the beacon. The reconnaissance behavior is unrelated to the declared CSS polyfill purpose and fires on any `require()` of the package.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.