CSS env() function shim for legacy browsers
The published registry script contains an active host reconnaissance and exfiltration payload. Its manifest provides a loading route despite the empty default entrypoint.
package.json publishes the registry script and manifest alongside the default entrypoint.
package.jsonView on unpkg · L5registry-manifest.min.json directs registry consumers to thunderboltRegistry.js.
registry-manifest.min.jsonView on unpkg · L2thunderboltRegistry.js decodes child_process and execSync, then dynamically loads the command execution module.
thunderboltRegistry.jsView on unpkg · L11thunderboltRegistry.js decodes child_process and execSync, then dynamically loads the command execution module.
thunderboltRegistry.jsView on unpkg · L35The script immediately runs commands collecting user identity, operating system, hosts file, network interfaces, and hostname.
thunderboltRegistry.jsView on unpkg · L53Command output is sent through fetch requests to an encoded webhook URL and output-bearing external subdomains.
thunderboltRegistry.jsView on unpkg · L45Command output is sent through fetch requests to an encoded webhook URL and output-bearing external subdomains.
thunderboltRegistry.jsView on unpkg · L21This report applies to css-env-function-shim@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
package.json publishes the registry script and manifest alongside the default entrypoint.
package.jsonView on unpkg · L5registry-manifest.min.json directs registry consumers to thunderboltRegistry.js.
registry-manifest.min.jsonView on unpkg · L2thunderboltRegistry.js decodes child_process and execSync, then dynamically loads the command execution module.
thunderboltRegistry.jsView on unpkg · L11Command output is sent through fetch requests to an encoded webhook URL and output-bearing external subdomains.
thunderboltRegistry.jsView on unpkg · L21thunderboltRegistry.js decodes child_process and execSync, then dynamically loads the command execution module.
thunderboltRegistry.jsView on unpkg · L35Command output is sent through fetch requests to an encoded webhook URL and output-bearing external subdomains.
thunderboltRegistry.jsView on unpkg · L45The script immediately runs commands collecting user identity, operating system, hosts file, network interfaces, and hostname.
thunderboltRegistry.jsView on unpkg · L53