OpenSSF/OSV advisory MAL-2026-17547 confirms this npm version as malicious. Package is published under a CSS-polyfill name but ships thunderboltRegistry.js, which exports Wix internal registry module names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) so that a build resolving any of those names will load this file. On require(), an IIFE runs child_process.execSync to collect `id`, `whoami`, `uname`, `ifconfig`/`ip addr`, and the contents of /etc/hosts,...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in css-at-scope-polyfill (npm)
Details
Package is published under a CSS-polyfill name but ships thunderboltRegistry.js, which exports Wix internal registry module names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) so that a build resolving any of those names will load this file. On require(), an IIFE runs child_process.execSync to collect `id`, `whoami`, `uname`, `ifconfig`/`ip addr`, and the contents of /etc/hosts, plus a beacon containing node version, platform, pid, and hostname, and POSTs the output via fetch to the hardcoded HTTP endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The payload clears any require.cache entries referencing 'thunderboltRegistry' and acquires child_process through three fallbacks, including instantiating a new Module via module.constructor to bypass mocks or sandboxes. The declared CSS-polyfill purpose has no relation to this behavior; the shape is a dependency-confusion squat against internal Wix modules.
Decision reason
OpenSSF Malicious Packages via OSV confirms css-at-scope-polyfill@1.0.0 as malicious (MAL-2026-17547): Malicious code in css-at-scope-polyfill (npm)