-= Per source details. Do not edit below this line.=-
css-ogojwh-polyfill@1.0.0 presents itself as a CSS polyfill but ships thunderboltRegistry.js which, on require, runs an IIFE that executes shell commands via child_process.execSync (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) and POSTs their output along with hostname, Node version, platform and pid to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f, with a beacon label of rce-poc. The module also exports no-op Proxy stubs under module names matching Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, editorRegistry), consistent with a dependency-confusion / typosquat shim whose only real behavior is the recon-and-exfil payload executed at import time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021017",
"import_time": "2026-10-05T03:57:39.04950358Z",
"modified_time": "2026-10-05T03:36:05Z",
"sha256": "aff543635c832e0563229f42fcc7673c835f2ba5a9ae41d680aa572cfba49765",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928",
"tlsh": "e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8"
}
],
"package_integrity": [
{
"filename": "css-ogojwh-polyfill-1.0.0.tgz",
"hashes": {
"sha1": "05e1e1171265d9abec7ed2e5eb8e77f251e04fc3",
"sha512_sri": "sha512-9J0X+2VJAshTo2Mvv1Chb1YdFp6lj3sxQ2nkMQc6+43W0h+lajwG99tGqcu574Rp63sldaWqmqKxaoqRmc8y1g=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-ogojwh-polyfill/MAL-2026-17556.json"