OpenSSF/OSV advisory MAL-2026-17558 confirms this npm version as malicious. thunderboltRegistry.js executes an IIFE at require time that runs OS reconnaissance commands (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) via child_process.execSync, URL-encodes the output together with hostname, node version, platform, and pid, and POSTs/GETs each result via fetch to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in css-txedrf-polyfill (npm)
Details
thunderboltRegistry.js executes an IIFE at require time that runs OS reconnaissance commands (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) via child_process.execSync, URL-encodes the output together with hostname, node version, platform, and pid, and POSTs/GETs each result via fetch to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP. The package's exported module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix thunderbolt internal registry modules and the manifest references static.parastorage.com URLs, consistent with a dependency-confusion lure aimed at a private Wix namespace. Any consumer that requires one of these modules triggers the reconnaissance and exfiltration to the attacker-controlled host.
Decision reason
OpenSSF Malicious Packages via OSV confirms css-txedrf-polyfill@1.0.0 as malicious (MAL-2026-17558): Malicious code in css-txedrf-polyfill (npm)