OpenSSF/OSV advisory MAL-2026-17578 confirms this npm version as malicious. css-yhpodl-polyfill ships thunderboltRegistry.js which, as an IIFE executed on require, runs shell reconnaissance (`id`, `whoami`, `env`, `ifconfig`/`ip addr`, hostname) via child_process.execSync and sends the collected host identity and full environment variables via GET to the hardcoded Burp Collaborator OAST endpoint https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/...
This report applies to css-yhpodl-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.