MAL-2026-17549

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-display-reading-polyfill/MAL-2026-17549.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17549
Published
2026-10-05T03:35:25Z
Modified
2026-10-05T04:15:06Z
Summary
Malicious code in css-display-reading-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b397798b7209f1094c33dc3ed721d4a3ef0536065317bd06bae76e33dd505334)

The package ships payload.bundle.min.js, which on load runs an IIFE that invokes child_process.execSync to run id, whoami, and uname, collects os.hostname(), node version, process.platform, and pid, and transmits the results to the hardcoded collector https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b via fetch and https.get. The published name impersonates an internal Wix thunderbolt module: shipped thunderbolt manifest JSON files declare this package as the loader entry for dozens of Wix component registry names (Container, StylableButton, MasterPage,...) and nine host registries (thunderboltRegistry, editorRegistry, corvidRegistry,...), with "shared":["payload.bundle.min.js"] and components mapped to that bundle. index.js is a benign stub; the exfil code lives entirely in the bundle, so any Wix runtime that resolves these internal registry names from this public package executes the host-reconnaissance payload. This is a dependency-confusion active attack: installer-side shell command output and host identifiers are sent to an attacker-controlled, non-first-party endpoint.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021013",
            "import_time":  "2026-10-05T03:57:38.660541152Z",
            "modified_time":  "2026-10-05T03:35:25Z",
            "sha256":  "b397798b7209f1094c33dc3ed721d4a3ef0536065317bd06bae76e33dd505334",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-display-reading-polyfill

Package

Name
css-display-reading-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-display-reading-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "payload.bundle.min.js",
            "sha256":  "3f778f66c94db7420b7a62ed859fd3fc10d86dd8cb5ea3a384e72804dead3fb7",
            "tlsh":  "fb6112a5b99db02166c33438cb7f9549f0bb95232d6caed0b40896f02f7585d02be5f8"
        },
        {
            "path":  "rb_wixui.thunderbolt.manifest.min.json",
            "sha256":  "34a5618b1f468592c484d6e055b533d3dc7f8b2859b470c5c4b29d4a9033b13d",
            "tlsh":  "3c41c91ad5148e6a5d413d2e31f3bf011d7660633d458f109679c39ecff9aa474d29c2"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-display-reading-polyfill-1.0.0.tgz",
            "hashes":  {
                "sha1":  "06f17a7ae31dab3c126c89382a5b1c0baefe3957",
                "sha512_sri":  "sha512-lbniva5SNHZlKBFiCtMgYMAD8nJ4qFkXYszL5zfyWlK3wZUpZCg2pA6mV4xJz0tmLKlb2SWH4WCpDJjYcb7dLw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-display-reading-polyfill/MAL-2026-17549.json"