MAL-2026-17525

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-css-token-parser/MAL-2026-17525.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17525
Published
2026-10-04T23:25:27Z
Modified
2026-10-04T23:45:21Z
Summary
Malicious code in tiny-css-token-parser (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f)

Package is advertised as a CSS token parser but ships thunderboltRegistry.js which runs an IIFE on module load that collects hostname, pid, Node version, platform, and the output of id and uname -r via child_process.execSync, then exfiltrates them as DNS/HTTP subdomains under an oast.live interact.sh collector and a POST to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a where=internetbrands tag. The package manifest aliases seven internal Wix Thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) to the same recon module and exports factories under those keys, so any loader that resolves those internal names to this public package will execute the recon payload. The name/description are a cover story; the actual behavior is targeted dependency-confusion reconnaissance against Wix's internetbrands build graph.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020954",
            "import_time":  "2026-10-04T23:40:45.509867136Z",
            "modified_time":  "2026-10-04T23:25:27Z",
            "sha256":  "ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / tiny-css-token-parser

Package

Name
tiny-css-token-parser
View open source insights on deps.dev
Purl
pkg:npm/tiny-css-token-parser

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "b2e3286b25a4faf31781cf3dc94d2821df31afa4b25f3c550dc5cb699e32c8e2",
            "tlsh":  "b651f5da78daf00193c274758dbf9045f07be9572978af88b80895b02f7246c107eaf8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "tiny-css-token-parser-1.0.0.tgz",
            "hashes":  {
                "sha1":  "1eb250f2ce0fc5aa80b6e88dd81d002fb214b009",
                "sha512_sri":  "sha512-UqOYEJzmbxTqsIw37/8MuIOze2/3p7ctUU2SapOGp9tJZdbj5TAwPu8XW5XbOVQeGeBfqbXRScd7FG/HjInuLw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-css-token-parser/MAL-2026-17525.json"