Polyfill for CSS scroll-state container queries
The published registry asset contains immediately executing host reconnaissance and data exfiltration. Its bundled manifest directs registry loaders to that asset.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgthunderboltRegistry.js sends collected data and the hostname to a fixed webhook.site URL.
thunderboltRegistry.jsView on unpkg · L11The registry code executes identity, system and network commands and forwards their output.
thunderboltRegistry.jsView on unpkg · L25The registry code reads /etc/hosts and forwards up to 2,000 characters.
thunderboltRegistry.jsView on unpkg · L45registry-manifest.min.json maps registry assets to the executable thunderboltRegistry.js URL.
registry-manifest.min.jsonView on unpkg · L2package.json includes the registry payload and manifest in published files.
package.jsonView on unpkg · L5This report applies to css-scroll-state-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
thunderboltRegistry.js sends collected data and the hostname to a fixed webhook.site URL.
thunderboltRegistry.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10The registry code executes identity, system and network commands and forwards their output.
thunderboltRegistry.jsView on unpkg · L25The registry code reads /etc/hosts and forwards up to 2,000 characters.
thunderboltRegistry.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgregistry-manifest.min.json maps registry assets to the executable thunderboltRegistry.js URL.
registry-manifest.min.jsonView on unpkg · L2package.json includes the registry payload and manifest in published files.
package.jsonView on unpkg · L5