MAL-2026-17477

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-env-function-shim/MAL-2026-17477.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17477
Published
2026-10-04T23:13:53Z
Modified
2026-10-04T23:30:05Z
Summary
Malicious code in css-env-function-shim (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (03e6fced50259d6d3781ef3917caba965e4744420188c3e06919541b64e2e294)

Package self-describes as a CSS env() shim but ships thunderboltRegistry.js, which runs an IIFE at module load that base64-decodes the strings 'child_process' and 'execSync', dynamically requires child_process, and shells out whoami, uname, cat /etc/hosts, ifconfig/ip addr, id, and hostname. The collected output is POSTed to a hardcoded webhook.site URL (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba) and beaconed to a subdomain of davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live for DNS exfiltration. All sensitive identifiers (module name, method name, commands, destination host, UUID path, OAST subdomain) are stored as base64 blobs or String.fromCharCode arrays and reconstructed at runtime to defeat static inspection. index.js is a stub; the module factory is re-exported under nine Wix-internal registry key names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and similar), and the shipped registry-manifest.min.json aliases numerous Wix thunderbolt *Registry.js URLs on parastorage.com to this package's thunderboltRegistry.js — a dependency-confusion lure targeting Wix's internal build so that any importer of those names triggers the exfiltration IIFE at require time.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020884",
            "import_time":  "2026-10-04T23:16:30.311679784Z",
            "modified_time":  "2026-10-04T23:13:53Z",
            "sha256":  "03e6fced50259d6d3781ef3917caba965e4744420188c3e06919541b64e2e294",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-env-function-shim

Package

Name
css-env-function-shim
View open source insights on deps.dev
Purl
pkg:npm/css-env-function-shim

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "e3de7ea4ec468ec5f0e47c839eb7d2097c875fac37040d89901075e9e12a9fa8",
            "tlsh":  "0a8172edb9d6a0051953647987bf200b71b7daa32d68c490f89ed5f42f70228843e7f9"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-env-function-shim-1.0.0.tgz",
            "hashes":  {
                "sha1":  "98d09e15e0a93d9d1166ed61d204f6d88a8a325e",
                "sha512_sri":  "sha512-HytTrAFrnD7uPPXmkggEqttDZNy81gBzz4dosHK0tNacsvxIHrnZgELaYyqmqeLawJG+pRRKfcelcQFesSSFEQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-env-function-shim/MAL-2026-17477.json"