-= Per source details. Do not edit below this line.=-
Package name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes id and uname -r via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020955",
"import_time": "2026-10-04T23:40:45.602923664Z",
"modified_time": "2026-10-04T23:25:38Z",
"sha256": "02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "32c55be50d08a10f5ca4ddd2a589076d60660f4f2fa50ae37a79e82ed7734531",
"tlsh": "cf51f5da78daf00193c274758dbf9045f07bed572978af88b80895b02f7246c107aaf8"
}
],
"package_integrity": [
{
"filename": "rgx33-flex-layout-core-1.0.0.tgz",
"hashes": {
"sha1": "e08058ae389de6d4860841fe5dd2f2be97abda36",
"sha512_sri": "sha512-WmcB0SObQ5nXHOVujReRu5vAlqbMFH6lHy5SK4Yxt/vcm7znjgyMHx4t34pqiieS8GIwXVHBO6EgX50wH1HFcw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-flex-layout-core/MAL-2026-17521.json"