css-reading-display-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-17656
Ecosystem
npm
Summary
thunderboltRegistry.js runs an IIFE at module load that invokes child_process.execSync to collect host identity (id, whoami, uname), the first 2000 bytes of the environment (env | head -100), network interfaces (ifconfig), and /etc/hosts, then transmits the results together with the hostname and Node version to a hardcoded webhook.site URL (https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418) via https.get and fetch. The package exports proxies for internal Wix thunderbolt registry names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, and others) with a manifest pointing at static.parastorage.com/unpkg/, and the beacon is labelled beacon=rce-poc, consistent with a dependency-confusion probe against Wix build infrastructure. The exfiltrated environment typically contains CI secrets and cloud credentials, giving an installer-side credential-theft blast radius wherever the build pipeline resolves these internal names to this package.
Source: amazon-inspector (a06a8966ab81cea21f3e94074bcdb0d72ea55a96be2d03989e12aa2f4d86ad66)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.