VYPR

npm · Malicious package advisory

Malware

css-reading-flow-polyfill

GHSA-h7h4-gh2m-xjmq

Malicious code in css-reading-flow-polyfill (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (3b18e313d5fc67f07c1bcf051bd79a85dca97bb3c4510d9755efca6414bb55ff)
The package is published as css-reading-flow-polyfill but ships thunderboltRegistry.js, which impersonates internal Wix thunderbolt registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) by exporting all of those names from a single payload file. On require, an IIFE in thunderboltRegistry.js uses child_process.execSync to run id, whoami, uname, ifconfig/ip-addr and read /etc/hosts, then fetches http://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f over plain HTTP with the command output, hostname, Node version, platform and pid appended as query parameters. The module also walks require.cache and deletes any entry whose key contains 'thunderboltRegistry' so the recon-and-exfil IIFE re-runs on every require rather than being cached. index.js is an empty decoy; the stated CSS polyfill purpose is a cover story and the package has no implementation of that functionality.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-reading-flow-polyfill/MAL-2026-17483.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-reading-flow-polyfill/MAL-2026-17483.json
- https://www.npmjs.com/package/css-reading-flow-polyfill/v/1.0.0
- https://github.com/advisories/GHSA-h7h4-gh2m-xjmq

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.