MAL-2026-17656

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-reading-display-polyfill/MAL-2026-17656.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17656
Published
2026-10-08T03:38:12Z
Modified
2026-10-08T05:00:05Z
Summary
Malicious code in css-reading-display-polyfill (npm)
Details

css-reading-display-polyfill is described as a CSS polyfill but contains no polyfill code. When its thunderboltRegistry.js is loaded, it runs id, whoami, uname -a, env, ifconfig and cat /etc/hosts and sends the output with the hostname to a webhook.site collector. The file also exports stubs named after Wix Thunderbolt registry modules. The environment variables are sent as well, so tokens and API keys stored in them can be leaked.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a06a8966ab81cea21f3e94074bcdb0d72ea55a96be2d03989e12aa2f4d86ad66)

thunderboltRegistry.js runs an IIFE at module load that invokes child_process.execSync to collect host identity (id, whoami, uname), the first 2000 bytes of the environment (env | head -100), network interfaces (ifconfig), and /etc/hosts, then transmits the results together with the hostname and Node version to a hardcoded webhook.site URL (https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418) via https.get and fetch. The package exports proxies for internal Wix thunderbolt registry names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, and others) with a manifest pointing at static.parastorage.com/unpkg/, and the beacon is labelled beacon=rce-poc, consistent with a dependency-confusion probe against Wix build infrastructure. The exfiltrated environment typically contains CI secrets and cloud credentials, giving an installer-side credential-theft blast radius wherever the build pipeline resolves these internal names to this package.

Database specific
{
    "iocs": {
        "files": [
            {
                "digests": {
                    "sha256": "6e496e946e615a29e2d3d4a2fca8c2356121c16cc22ee6121f4a230d4414e60d"
                },
                "note": "Payload. Runs host commands and sends their output to the collector when the file is loaded.",
                "paths": [
                    "thunderboltRegistry.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "d4e09cedb8754efefe9bff9bbc1e492cf55ee16f92f0db2b639a70d90b94ec92"
                },
                "note": "Maps Wix-internal registry names to thunderboltRegistry.js.",
                "paths": [
                    "registry-manifest.min.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            }
        ],
        "urls": [
            "https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021115",
            "import_time": "2026-10-08T03:50:28.884428541Z",
            "modified_time": "2026-10-08T03:38:12Z",
            "sha256": "a06a8966ab81cea21f3e94074bcdb0d72ea55a96be2d03989e12aa2f4d86ad66",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-reading-display-polyfill

Package

Name
css-reading-display-polyfill
View open source insights on deps.dev
Purl
pkg:npm/css-reading-display-polyfill

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "thunderboltRegistry.js",
            "sha256": "6e496e946e615a29e2d3d4a2fca8c2356121c16cc22ee6121f4a230d4414e60d",
            "tlsh": "35812fb5b99db02065c33478cb7f5049b4bbc6672c6caee074499ab01f3985901ba6f4"
        }
    ],
    "package_integrity": [
        {
            "filename": "css-reading-display-polyfill-1.0.0.tgz",
            "hashes": {
                "sha1": "166fb511ac3fc8dcc0e09728f152b329c69d5139",
                "sha512_sri": "sha512-thqpCoKMH/5iXKY/Ao3LLvW4IYxCHs8R+WH6BywvItnBN55nBHnV0VatLQMzkUgtJ/0HfXZxFUcEGYxj4WpYew=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-reading-display-polyfill/MAL-2026-17656.json"