MAL-2026-17520

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-css-grid-utils/MAL-2026-17520.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17520
Published
2026-10-04T23:26:04Z
Modified
2026-10-04T23:45:18Z
Summary
Malicious code in rgx33-css-grid-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5)

The package is published as rgx33-css-grid-utils but exports a set of module keys matching Wix thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, documentManagementRegistry, and others) — a dependency-confusion lure targeting Wix's internal build/runtime namespace. On module load, an IIFE collects host identifiers (hostname, pid, Node version, platform) and runs child_process.execSync('id') and child_process.execSync('uname -r') to capture the current user and kernel version. These values are encoded as DNS subdomain labels and sent via fetch to the interactsh/OOB collector davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live, and in parallel to https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a where=wix-blog query parameter identifying the campaign target. The package ships no CSS grid functionality consistent with its name; the reconnaissance beacon is the entire payload.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020958",
            "import_time":  "2026-10-04T23:40:45.887559116Z",
            "modified_time":  "2026-10-04T23:26:04Z",
            "sha256":  "320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / rgx33-css-grid-utils

Package

Name
rgx33-css-grid-utils
View open source insights on deps.dev
Purl
pkg:npm/rgx33-css-grid-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "b17cbd0463d9833f1510f074c8c5c7e2bcd4d43a7fcf957c779cf696b7e0b9a2",
            "tlsh":  "6651f5da78def00193c274758dbf9045f07be9572978ab98b80895b02f7146c107aaf8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "rgx33-css-grid-utils-1.0.0.tgz",
            "hashes":  {
                "sha1":  "40e95d482c657afdf564d3b2bf5fc4f9add5953c",
                "sha512_sri":  "sha512-UXQdLsdvq8JT1cIFFmTlbmpeDNG5mC8E9hiQKiwYaBvZvvr6of4uXJKWiWhGkXLdVzP/E2peqCCGOAz78bjW2Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-css-grid-utils/MAL-2026-17520.json"