OpenSSF/OSV advisory MAL-2026-17577 confirms this npm version as malicious. thunderboltRegistry.js runs an IIFE on module require that performs two attacker-benefit actions against the installer. First, it execSyncs `id`, `whoami`, `env`, and `ifconfig`/`ip addr`, then transmits the output along with hostname, platform, and pid as query parameters via fetch to a hardcoded unique-subdomain Burp Collaborator endpoint at https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/...
This report applies to css-vvgsze-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.