CSS polyfill utility
The bundled registry script contains active data exfiltration and remote code execution. Its manifest exposes that script to registry consumers.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10thunderboltRegistry.js immediately collects environment variables through a shell command and forwards the output.
thunderboltRegistry.jsView on unpkg · L35The script sends collected data and the hostname to an external tracking endpoint.
thunderboltRegistry.jsView on unpkg · L11The script downloads JavaScript from https://appsecc.com/js and pipes it directly to Node for execution.
thunderboltRegistry.jsView on unpkg · L45registry-manifest.min.json directs registry consumers to thunderboltRegistry.js.
registry-manifest.min.jsonView on unpkg · L2This report applies to css-jptvix-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The script sends collected data and the hostname to an external tracking endpoint.
thunderboltRegistry.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10thunderboltRegistry.js immediately collects environment variables through a shell command and forwards the output.
thunderboltRegistry.jsView on unpkg · L35The script downloads JavaScript from https://appsecc.com/js and pipes it directly to Node for execution.
thunderboltRegistry.jsView on unpkg · L45registry-manifest.min.json directs registry consumers to thunderboltRegistry.js.
registry-manifest.min.jsonView on unpkg · L2