OpenSSF/OSV advisory MAL-2026-17555 confirms this npm version as malicious. The package impersonates Wix thunderbolt internal registry modules (exporting `thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, etc. and shipping a `registry-manifest.min.json` referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in css-nbanqq-polyfill (npm)
Details
The package impersonates Wix thunderbolt internal registry modules (exporting `thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, etc. and shipping a `registry-manifest.min.json` referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run `id`, `whoami`, `uname -a`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.
Decision reason
OpenSSF Malicious Packages via OSV confirms css-nbanqq-polyfill@1.0.0 as malicious (MAL-2026-17555): Malicious code in css-nbanqq-polyfill (npm)