-= Per source details. Do not edit below this line.=-
Package is published as css-scroll-anchor-polyfill but its index.js is empty and its contents impersonate internal Wix thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) with a shipped registry-manifest.min.json mapping them to parastorage.com URLs. The declared purpose (a CSS scroll-anchor polyfill) is unrelated to the shipped code. thunderboltRegistry.js contains a top-level IIFE that executes on require: it runs local reconnaissance via child_process.execSync (cat /etc/hosts, whoami, id, pwd, ifconfig/ip addr, hostname, uname -a) and transmits the collected output together with a beacon (node version, process.platform, pid) via fetch to a hardcoded HTTP endpoint at http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. Any internal build that resolves one of the impersonated thunderbolt names to this public package and requires the corresponding submodule triggers the reconnaissance and exfiltration path.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020890",
"import_time": "2026-10-04T23:16:30.660101652Z",
"modified_time": "2026-10-04T23:14:52Z",
"sha256": "36596ba9b9d8c0f994abe3cd87783f4f0dc880e63d55374d3555347ce349fab2",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "52502bae08a507aee56838bd56d869c6afb9d16fecb344faf2b8a36912aba1f0",
"tlsh": "718130a5b99df020a6c33438cb7f504aa4bb86672c6caee0744d59b01f7985802ba5f4"
}
],
"package_integrity": [
{
"filename": "css-scroll-anchor-polyfill-1.0.0.tgz",
"hashes": {
"sha1": "f8796c49583ab0c011e8ada9a2c63a3245cd552f",
"sha512_sri": "sha512-ckKQkApTPEK4Thq2VMtVo36YoBRU1pgTo2GV6YKFeIJAUvoUd9hrvBrFP8/LZAj5Ietejx3zHyG6f3XaqLgZSg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-scroll-anchor-polyfill/MAL-2026-17485.json"