OpenSSF/OSV advisory MAL-2026-17553 confirms this npm version as malicious. The package presents itself as a CSS polyfill but ships thunderboltRegistry.js, which on require() executes a top-level IIFE that runs id, whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts via child_process.execSync, then posts the command outputs together with hostname, node version, platform, and pid to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/ using fetch...
This report applies to css-ikomdq-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.