{"id":"MAL-2026-17549","summary":"Malicious code in css-display-reading-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b397798b7209f1094c33dc3ed721d4a3ef0536065317bd06bae76e33dd505334)\nThe package ships payload.bundle.min.js, which on load runs an IIFE that invokes child_process.execSync to run id, whoami, and uname, collects os.hostname(), node version, process.platform, and pid, and transmits the results to the hardcoded collector https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b via fetch and https.get. The published name impersonates an internal Wix thunderbolt module: shipped thunderbolt manifest JSON files declare this package as the loader entry for dozens of Wix component registry names (Container, StylableButton, MasterPage,...) and nine host registries (thunderboltRegistry, editorRegistry, corvidRegistry,...), with \"shared\":[\"payload.bundle.min.js\"] and components mapped to that bundle. index.js is a benign stub; the exfil code lives entirely in the bundle, so any Wix runtime that resolves these internal registry names from this public package executes the host-reconnaissance payload. This is a dependency-confusion active attack: installer-side shell command output and host identifiers are sent to an attacker-controlled, non-first-party endpoint.\n","modified":"2026-10-05T04:15:06.606709710Z","published":"2026-10-05T03:35:25Z","database_specific":{"malicious-packages-origins":[{"sha256":"b397798b7209f1094c33dc3ed721d4a3ef0536065317bd06bae76e33dd505334","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021013","import_time":"2026-10-05T03:57:38.660541152Z","modified_time":"2026-10-05T03:35:25Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-display-reading-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-display-reading-polyfill","ecosystem":"npm","purl":"pkg:npm/css-display-reading-polyfill"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-display-reading-polyfill/MAL-2026-17549.json","indicators":{"evidence_files":[{"path":"payload.bundle.min.js","sha256":"3f778f66c94db7420b7a62ed859fd3fc10d86dd8cb5ea3a384e72804dead3fb7","tlsh":"fb6112a5b99db02166c33438cb7f9549f0bb95232d6caed0b40896f02f7585d02be5f8"},{"path":"rb_wixui.thunderbolt.manifest.min.json","sha256":"34a5618b1f468592c484d6e055b533d3dc7f8b2859b470c5c4b29d4a9033b13d","tlsh":"3c41c91ad5148e6a5d413d2e31f3bf011d7660633d458f109679c39ecff9aa474d29c2"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-lbniva5SNHZlKBFiCtMgYMAD8nJ4qFkXYszL5zfyWlK3wZUpZCg2pA6mV4xJz0tmLKlb2SWH4WCpDJjYcb7dLw==","sha1":"06f17a7ae31dab3c126c89382a5b1c0baefe3957"},"filename":"css-display-reading-polyfill-1.0.0.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}