Vulnerability MAL-2026-17656

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 hours ago
October 08, 2026 at 03:38 AM UTC
Malicious code in css-reading-display-polyfill (npm)
1.0.0
1.0.0

Summary

Malicious code in css-reading-display-polyfill (npm)

Details

css-reading-display-polyfill is described as a CSS polyfill but contains no polyfill code. When its thunderboltRegistry.js is loaded, it runs id, whoami, uname -a, env, ifconfig and cat /etc/hosts and sends the output with the hostname to a webhook.site collector. The file also exports stubs named after Wix Thunderbolt registry modules. The environment variables are sent as well, so tokens and API keys stored in them can be leaked.

Timeline

Published
4 hours ago
October 08, 2026 at 03:38 AM UTC
Last Modified
3 hours ago
October 08, 2026 at 05:00 AM UTC