MAL-2026-17521

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-flex-layout-core/MAL-2026-17521.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17521
Published
2026-10-04T23:25:38Z
Modified
2026-10-04T23:45:19Z
Summary
Malicious code in rgx33-flex-layout-core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb)

Package name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes id and uname -r via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020955",
            "import_time":  "2026-10-04T23:40:45.602923664Z",
            "modified_time":  "2026-10-04T23:25:38Z",
            "sha256":  "02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / rgx33-flex-layout-core

Package

Name
rgx33-flex-layout-core
View open source insights on deps.dev
Purl
pkg:npm/rgx33-flex-layout-core

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "32c55be50d08a10f5ca4ddd2a589076d60660f4f2fa50ae37a79e82ed7734531",
            "tlsh":  "cf51f5da78daf00193c274758dbf9045f07bed572978af88b80895b02f7246c107aaf8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "rgx33-flex-layout-core-1.0.0.tgz",
            "hashes":  {
                "sha1":  "e08058ae389de6d4860841fe5dd2f2be97abda36",
                "sha512_sri":  "sha512-WmcB0SObQ5nXHOVujReRu5vAlqbMFH6lHy5SK4Yxt/vcm7znjgyMHx4t34pqiieS8GIwXVHBO6EgX50wH1HFcw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-flex-layout-core/MAL-2026-17521.json"