MAL-2026-17575

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17575
Published
2026-10-05T16:14:25Z
Modified
2026-10-05T16:31:36Z
Summary
Malicious code in css-kfvwax-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df)

On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (id, whoami, uname -a), network interface listings (ifconfig/ip addr), and the contents of /etc/hosts, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021077",
            "import_time":  "2026-10-05T16:22:56.858031177Z",
            "modified_time":  "2026-10-05T16:14:25Z",
            "sha256":  "2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-kfvwax-polyfill

Package

Name
css-kfvwax-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-kfvwax-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "eea1ba8ba61d690d808a52ef7fec1a4115e5f322572c5c6241a6dfbcc3223abe",
            "tlsh":  "b47153a5b99df02166c33438cb7f5049b4bbc6672c6caee0740899b02f7985c01be6f5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-kfvwax-polyfill-1.0.0.tgz",
            "hashes":  {
                "sha1":  "11eafd4ac50d3d8cb64cda2a17520f203c5624cc",
                "sha512_sri":  "sha512-lURemH1bGmfUVRgvkECW9FjDD3pPZhb7pHailTz4l15DmcEz+R8qBaKJ+cZSSs5dEgplBhX+apDEsyBLGdqDsg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json"