MAL-2026-17483

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-reading-flow-polyfill/MAL-2026-17483.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17483
Published
2026-10-04T23:15:00Z
Modified
2026-10-04T23:30:04Z
Summary
Malicious code in css-reading-flow-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3b18e313d5fc67f07c1bcf051bd79a85dca97bb3c4510d9755efca6414bb55ff)

The package is published as css-reading-flow-polyfill but ships thunderboltRegistry.js, which impersonates internal Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) by exporting all of those names from a single payload file. On require, an IIFE in thunderboltRegistry.js uses child_process.execSync to run id, whoami, uname, ifconfig/ip-addr and read /etc/hosts, then fetches http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP with the command output, hostname, Node version, platform and pid appended as query parameters. The module also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry' so the recon-and-exfil IIFE re-runs on every require rather than being cached. index.js is an empty decoy; the stated CSS polyfill purpose is a cover story and the package has no implementation of that functionality.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020891",
            "import_time":  "2026-10-04T23:16:30.715858462Z",
            "modified_time":  "2026-10-04T23:15:00Z",
            "sha256":  "3b18e313d5fc67f07c1bcf051bd79a85dca97bb3c4510d9755efca6414bb55ff",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-reading-flow-polyfill

Package

Name
css-reading-flow-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-reading-flow-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "a485cb48081ea590cab385a405886cfe6f30af7d415f30bc8d7937ace461b928",
            "tlsh":  "e87154a5b99df02065c33438cb7f4049b4bbc6672d6caee0744899b01f7985c01be6f8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-reading-flow-polyfill-1.0.0.tgz",
            "hashes":  {
                "sha1":  "36edb37db10667ce91bddab337b927f64ed6c6f2",
                "sha512_sri":  "sha512-MnC2wHnnGNx+pPgectXQkaiR8hM3x234cdZOwKjsr5kLe3T5yhcEd/vzxmc4U29Q6qTVhPfDxF5g3ujzhAw5Sg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-reading-flow-polyfill/MAL-2026-17483.json"