OpenSSF/OSV advisory MAL-2026-17551 confirms this npm version as malicious. css-gvqmfn-polyfill mimics Wix internal @wix/thunderbolt-* CSS polyfill naming and ships a Proxy-based cover stub that re-exports registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) as no-op functions to appear functional. On require of thunderboltRegistry.js, an IIFE unconditionally executes `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts` via...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in css-gvqmfn-polyfill (npm)
Details
css-gvqmfn-polyfill mimics Wix internal @wix/thunderbolt-* CSS polyfill naming and ships a Proxy-based cover stub that re-exports registry names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) as no-op functions to appear functional. On require of thunderboltRegistry.js, an IIFE unconditionally executes `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts` via child_process, collects os.hostname, Node version, platform, and pid, and sends the output together with an `rce-poc` beacon to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP. The accompanying registry-manifest.min.json points sibling registries to parastorage.com URLs that do not host this file, consistent with a dependency-confusion lure targeting Wix build environments.
Decision reason
OpenSSF Malicious Packages via OSV confirms css-gvqmfn-polyfill@1.0.0 as malicious (MAL-2026-17551): Malicious code in css-gvqmfn-polyfill (npm)