VYPR

npm · Malicious package advisory

Malware

css-interop-observer-polyfill

MAL-2026-17480

Malicious code in css-interop-observer-polyfill (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (089bdc1dd6bdf0216bb911888e81ce97dc171bdef2588fd5de0aadb4a64fbb2b)
On module load, thunderboltRegistry.js executes an IIFE that runs id, whoami, uname, ifconfig/ip addr via child_process.execSync and reads /etc/hosts, then sends each result together with hostname, node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/[token] via fetch over plain HTTP. The package presents itself as a stub exporting proxies for Wix thunderbolt internal registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), consistent with dependency-confusion targeting of those internal module names while the load-time code performs the host reconnaissance and exfiltration.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.