css-display-reading-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17549
Ecosystem
npm
Summary
The package ships payload.bundle.min.js, which on load runs an IIFE that invokes child_process.execSync to run id, whoami, and uname, collects os.hostname(), node version, process.platform, and pid, and transmits the results to the hardcoded collector https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b via fetch and https.get. The published name impersonates an internal Wix thunderbolt module: shipped thunderbolt manifest JSON files declare this package as the loader entry for dozens of Wix component registry names (Container, StylableButton, MasterPage,...) and nine host registries (thunderboltRegistry, editorRegistry, corvidRegistry,...), with "shared":["payload.bundle.min.js"] and components mapped to that bundle. index.js is a benign stub; the exfil code lives entirely in the bundle, so any Wix runtime that resolves these internal registry names from this public package executes the host-reconnaissance payload. This is a dependency-confusion active attack: installer-side shell command output and host identifiers are sent to an attacker-controlled, non-first-party endpoint.
Source: amazon-inspector (b397798b7209f1094c33dc3ed721d4a3ef0536065317bd06bae76e33dd505334)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.