css-reading-order-polyfill@0.0.0-stage
Malicious code in css-reading-order-polyfill (npm)
Analysis
css-reading-order-polyfill@0.0.0-stage contains no executable code: the published tarball is 348 bytes unpacked and holds only package.json and README.md. The manifest sets "stub": true, describes itself as a "Temporary package placeholder for staged publishing", and uses the version string 0.0.0-stage; there is no repository, no license, no bin entry, no lifecycle hook, and no JavaScript. The README states the version is a temporary placeholder awaiting a staged release. This is a name-reservation publish: a plausible-sounding CSS polyfill name is claimed with an inert stub, positioned to be replaced by a functional payload in a later version. This version has no network activity and no IOCs (no C2 host, URL, IP, or dropped file) — the risk is the reserved package name and the expected follow-up release. Analysis of this version is metadata-only; no payload exists to characterise.
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 12:34 AM
- analyzed
- Oct 5, 2026, 06:28 PM
Related advisories
- css-display-reading-polyfill@1.0.0
- botmaker-cli@0.1.19
- @pinecone-experience/messages@99.9.1
- hardhat-spack@3.0.2
- solidity-gas-watcher@2.21.0
- @airbnb-extended/typescript-config@99.9.1
- velocity-sdk-ui@1.0.0
- wallet-connect-adapter@1.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.