-= Per source details. Do not edit below this line.=-
On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (id, whoami, uname -a), network interface listings (ifconfig/ip addr), and the contents of /etc/hosts, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021077",
"import_time": "2026-10-05T16:22:56.858031177Z",
"modified_time": "2026-10-05T16:14:25Z",
"sha256": "2041e61cd16558aaaeac8a2f26024866a6b949d93817f78de744c5c1781023df",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "eea1ba8ba61d690d808a52ef7fec1a4115e5f322572c5c6241a6dfbcc3223abe",
"tlsh": "b47153a5b99df02166c33438cb7f5049b4bbc6672c6caee0740899b02f7985c01be6f5"
}
],
"package_integrity": [
{
"filename": "css-kfvwax-polyfill-1.0.0.tgz",
"hashes": {
"sha1": "11eafd4ac50d3d8cb64cda2a17520f203c5624cc",
"sha512_sri": "sha512-lURemH1bGmfUVRgvkECW9FjDD3pPZhb7pHailTz4l15DmcEz+R8qBaKJ+cZSSs5dEgplBhX+apDEsyBLGdqDsg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-kfvwax-polyfill/MAL-2026-17575.json"