css-reading-display-polyfill@1.0.0
Malicious code in css-reading-display-polyfill (npm)
Analysis
css-reading-display-polyfill@1.0.0 is a trojanized clone of Wix's thunderboltRegistry module that exfiltrates host and environment data on require. The package's index.js is an empty stub; the payload lives in package/thunderboltRegistry.js, which is also aliased by package/registry-manifest.min.json to eight Wix registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry, corvidRegistry, dataBindingRegistry), so any consumer requiring one of those names loads the malicious file. On load the script deletes its own require.cache entry, then uses child_process.execSync to run `id`, `id -un`/`whoami`, `uname -a`, `env | head -100`, `ifconfig`/`ip addr`, and `cat /etc/hosts`, URL-encoding each result and sending it via both fetch() and https.get() to hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418, followed by a beacon containing node version, platform, and pid. The `env` dump exposes CI/registry credentials such as NPM_TOKEN, GITHUB_TOKEN, and cloud keys to the attacker. IOCs: C2 hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (host webhook[.]site, port 443); exfiltrated fields cmd=id, cmd=whoami, cmd=uname, cmd=env, cmd=ifconfig, cmd=cat-etc-hosts, beacon=rce-poc.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 10:46 PM
- analyzed
- Oct 6, 2026, 10:50 PM
Related advisories
- css-jptvix-polyfill@1.0.0
- @worrisome/aaaa@1.0.0
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- zomato-server@1.0.0
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
- css-flow-render-shim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.