Skip to content

Malicious code in css-scroll-state-polyfill (npm)

Malware Published Oct 5, 2026 to the GitHub Advisory Database • Updated Oct 5, 2026

Package

npm css-scroll-state-polyfill (npm)

Affected versions

= 1.0.0

Patched versions

None

Description

Source: amazon-inspector (cffa0affc34bac3fa24fcc7c67aae4d120066f4f856cb8b637bc04c6ca9d482c)

The package presents itself as a CSS polyfill but ships a payload file (thunderboltRegistry.js) that executes an IIFE at require time. The IIFE uses child_process to run host-identification commands (id, whoami, uname -a, ifconfig/ip addr, /etc/hosts, hostname) and collects Node version, platform, and PID, then sends the captured data via fetch to a hardcoded webhook.site collector at https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The main index.js is an empty stub; filenames mimic internal Wix Thunderbolt registry modules, consistent with a dependency-confusion squat targeting that namespace. A self-identifying 'beacon=poc15' tag is included in the request. The payload also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry', causing subsequent requires in the same process to re-execute the recon-and-exfiltration path rather than return a cached export, and exports a Proxy that answers arbitrary method accesses to blend in with the impersonated registry.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Oct 5, 2026
Reviewed Oct 5, 2026
Last updated Oct 5, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-wwwp-g75q-ww7r

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.