CSS polyfill utility
The published registry module automatically collects system information and sends it to an external callback when loaded.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgthunderboltRegistry.js sends collected data and the hostname to a fixed external HTTP callback.
thunderboltRegistry.jsView on unpkg · L11Loading thunderboltRegistry.js immediately executes system commands and forwards their output.
thunderboltRegistry.jsView on unpkg · L25The module reads /etc/hosts and sends its contents to the callback.
thunderboltRegistry.jsView on unpkg · L45registry-manifest.min.json maps registry assets to the executable module.
registry-manifest.min.jsonView on unpkg · L2package.json explicitly includes the registry manifest and executable module in published files.
package.jsonView on unpkg · L5This report applies to css-hgwctv-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
thunderboltRegistry.js sends collected data and the hostname to a fixed external HTTP callback.
thunderboltRegistry.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10Loading thunderboltRegistry.js immediately executes system commands and forwards their output.
thunderboltRegistry.jsView on unpkg · L25The module reads /etc/hosts and sends its contents to the callback.
thunderboltRegistry.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgregistry-manifest.min.json maps registry assets to the executable module.
registry-manifest.min.jsonView on unpkg · L2package.json explicitly includes the registry manifest and executable module in published files.
package.jsonView on unpkg · L5