css-reading-display-polyfill is described as a CSS polyfill but contains no polyfill code. When its thunderboltRegistry.js is loaded, it runs id, whoami, uname -a, env, ifconfig and cat /etc/hosts and sends the output with the hostname to a webhook.site collector. The file also exports stubs named after Wix Thunderbolt registry modules. The environment variables are sent as well, so tokens and API keys stored in them can be leaked.
-= Per source details. Do not edit below this line.=-
thunderboltRegistry.js runs an IIFE at module load that invokes child_process.execSync to collect host identity (id, whoami, uname), the first 2000 bytes of the environment (env | head -100), network interfaces (ifconfig), and /etc/hosts, then transmits the results together with the hostname and Node version to a hardcoded webhook.site URL (https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418) via https.get and fetch. The package exports proxies for internal Wix thunderbolt registry names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, and others) with a manifest pointing at static.parastorage.com/unpkg/, and the beacon is labelled beacon=rce-poc, consistent with a dependency-confusion probe against Wix build infrastructure. The exfiltrated environment typically contains CI secrets and cloud credentials, giving an installer-side credential-theft blast radius wherever the build pipeline resolves these internal names to this package.
{
"iocs": {
"files": [
{
"digests": {
"sha256": "6e496e946e615a29e2d3d4a2fca8c2356121c16cc22ee6121f4a230d4414e60d"
},
"note": "Payload. Runs host commands and sends their output to the collector when the file is loaded.",
"paths": [
"thunderboltRegistry.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "d4e09cedb8754efefe9bff9bbc1e492cf55ee16f92f0db2b639a70d90b94ec92"
},
"note": "Maps Wix-internal registry names to thunderboltRegistry.js.",
"paths": [
"registry-manifest.min.json"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021115",
"import_time": "2026-10-08T03:50:28.884428541Z",
"modified_time": "2026-10-08T03:38:12Z",
"sha256": "a06a8966ab81cea21f3e94074bcdb0d72ea55a96be2d03989e12aa2f4d86ad66",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "6e496e946e615a29e2d3d4a2fca8c2356121c16cc22ee6121f4a230d4414e60d",
"tlsh": "35812fb5b99db02065c33478cb7f5049b4bbc6672c6caee074499ab01f3985901ba6f4"
}
],
"package_integrity": [
{
"filename": "css-reading-display-polyfill-1.0.0.tgz",
"hashes": {
"sha1": "166fb511ac3fc8dcc0e09728f152b329c69d5139",
"sha512_sri": "sha512-thqpCoKMH/5iXKY/Ao3LLvW4IYxCHs8R+WH6BywvItnBN55nBHnV0VatLQMzkUgtJ/0HfXZxFUcEGYxj4WpYew=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-reading-display-polyfill/MAL-2026-17656.json"