MAL-2026-17555

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-nbanqq-polyfill/MAL-2026-17555.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17555
Published
2026-10-05T03:35:45Z
Modified
2026-10-05T04:15:06Z
Summary
Malicious code in css-nbanqq-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f)

The package impersonates Wix thunderbolt internal registry modules (exporting thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc. and shipping a registry-manifest.min.json referencing static.parastorage.com) as a dependency-confusion lure. On require of thunderboltRegistry.js, a top-level IIFE uses child_process.execSync to run id, whoami, uname -a, ifconfig/ip addr, and cat /etc/hosts, URL-encodes the output together with hostname, Node version, platform, and pid, and sends it via fetch to the hardcoded attacker endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. Proxy-wrapped stubs make the require() call appear to resolve normally while the exfiltration runs. Any build or runtime that resolves this package name will execute the reconnaissance payload and leak host identity and network configuration to the attacker-controlled host.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021015",
            "import_time":  "2026-10-05T03:57:38.808911914Z",
            "modified_time":  "2026-10-05T03:35:45Z",
            "sha256":  "7377a70c94f8fd1719147b2023860926935a70410f672e07411326284f11a69f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-nbanqq-polyfill

Package

Name
css-nbanqq-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-nbanqq-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928",
            "tlsh":  "e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-nbanqq-polyfill-1.0.0.tgz",
            "hashes":  {
                "sha1":  "173ab1b2e46712e9da9269c952e43aca1d2763d6",
                "sha512_sri":  "sha512-waeHo5RpZ3D01CpUL8ZvjNwC5UUJetTCLMWk7Um5lJViHp0RpW/fQHRF73ZjkO3uw7gaaIP2fTNPlGj45Ovdlg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-nbanqq-polyfill/MAL-2026-17555.json"