css-display-reading-polyfill@1.0.0
Malicious code in css-display-reading-polyfill (npm)
Analysis
css-display-reading-polyfill@1.0.0 ships a trojanized copy of the Wix Thunderbolt runtime bundle. The bundled file payload.bundle.min.js executes a top-level IIFE as soon as the module is loaded: it first deletes require.cache entries whose paths contain "payload", "rb_wixui", "rb_dsgnsys" or "model" to conceal itself, then runs shell commands through child_process.execSync — `id -un`/`whoami`, `id`, and `uname -a` — and sends the output, together with os.hostname(), process.version, process.platform and process.pid, to the hardcoded endpoint hxxps://webhook[.]site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b using both fetch() and https.get() as fallbacks, tagged with query parameters cmd=, out=, site=, beacon=topology-rce and vector=registryLibrariesTopology. The remainder of the file is a Proxy-based stub factory that exports fake thunderboltRegistry/siteAssetsRegistry/editorRegistry/... hosts so the module appears to be a working Wix runtime. index.js is an empty stub and package.json declares no lifecycle scripts or bin entries, so the payload fires when payload.bundle.min.js is required; the shipped Wix manifests rb_wixui.thunderbolt.manifest.min.json and rb_dsgnsys.thunderbolt.manifest.min.json reference that file as the shared/model bundle and point their baseURL at static[.]parastorage[.]com/unpkg/css-display-reading-polyfill@1.0.0/. No credentials, tokens or local files are read — the exfiltrated data is host, user and OS fingerprinting.
- analyzed by
- Leitwacht
- first seen
- Oct 4, 2026, 06:21 PM
- analyzed
- Oct 5, 2026, 06:27 PM
Related advisories
- tailwind-form-kit@0.6.2
- cbc97b7a@1.1787999998.0
- sbman@1.0.0
- sbironman@1.0.0
- wormgpt-cli@1.0.1
- osinthell@1.9.5
- delta-time-32bb@1.0.0
- css-flow-render-shim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.