css-reading-flow-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17483
Ecosystem
npm
Summary
The package is published as css-reading-flow-polyfill but ships thunderboltRegistry.js, which impersonates internal Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) by exporting all of those names from a single payload file. On require, an IIFE in thunderboltRegistry.js uses child_process.execSync to run id, whoami, uname, ifconfig/ip-addr and read /etc/hosts, then fetches http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP with the command output, hostname, Node version, platform and pid appended as query parameters. The module also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry' so the recon-and-exfil IIFE re-runs on every require rather than being cached. index.js is an empty decoy; the stated CSS polyfill purpose is a cover story and the package has no implementation of that functionality.
Source: amazon-inspector (3b18e313d5fc67f07c1bcf051bd79a85dca97bb3c4510d9755efca6414bb55ff)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.