OpenSSF/OSV advisory MAL-2026-17525 confirms this npm version as malicious. Package is advertised as a CSS token parser but ships thunderboltRegistry.js which runs an IIFE on module load that collects hostname, pid, Node version, platform, and the output of `id` and `uname -r` via child_process.execSync, then exfiltrates them as DNS/HTTP subdomains under an oast.live interact.sh collector and a POST to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a `where=internetbrands` tag...
This report applies to tiny-css-token-parser@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.