npm · Malicious package advisory
Malwarecss-interop-observer-polyfill
MAL-2026-17480
Malicious code in css-interop-observer-polyfill (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (089bdc1dd6bdf0216bb911888e81ce97dc171bdef2588fd5de0aadb4a64fbb2b) On module load, thunderboltRegistry.js executes an IIFE that runs id, whoami, uname, ifconfig/ip addr via child_process.execSync and reads /etc/hosts, then sends each result together with hostname, node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/[token] via fetch over plain HTTP. The package presents itself as a stub exporting proxies for Wix thunderbolt internal registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), consistent with dependency-confusion targeting of those internal module names while the load-time code performs the host reconnaissance and exfiltration.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.