-= Per source details. Do not edit below this line.=-
Package is advertised as a CSS token parser but ships thunderboltRegistry.js which runs an IIFE on module load that collects hostname, pid, Node version, platform, and the output of id and uname -r via child_process.execSync, then exfiltrates them as DNS/HTTP subdomains under an oast.live interact.sh collector and a POST to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a where=internetbrands tag. The package manifest aliases seven internal Wix Thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) to the same recon module and exports factories under those keys, so any loader that resolves those internal names to this public package will execute the recon payload. The name/description are a cover story; the actual behavior is targeted dependency-confusion reconnaissance against Wix's internetbrands build graph.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020954",
"import_time": "2026-10-04T23:40:45.509867136Z",
"modified_time": "2026-10-04T23:25:27Z",
"sha256": "ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "b2e3286b25a4faf31781cf3dc94d2821df31afa4b25f3c550dc5cb699e32c8e2",
"tlsh": "b651f5da78daf00193c274758dbf9045f07be9572978af88b80895b02f7246c107eaf8"
}
],
"package_integrity": [
{
"filename": "tiny-css-token-parser-1.0.0.tgz",
"hashes": {
"sha1": "1eb250f2ce0fc5aa80b6e88dd81d002fb214b009",
"sha512_sri": "sha512-UqOYEJzmbxTqsIw37/8MuIOze2/3p7ctUU2SapOGp9tJZdbj5TAwPu8XW5XbOVQeGeBfqbXRScd7FG/HjInuLw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-css-token-parser/MAL-2026-17525.json"