-= Per source details. Do not edit below this line.=-
The package advertises itself as a CSS overscroll-behavior utility but its shipped modules (thunderboltRegistry.js and sibling files named after Wix-internal registries such as siteAssetsRegistry, editorRegistry, corvidRegistry) run a self-executing IIFE at module load that performs host reconnaissance and bulk credential theft. The IIFE uses child_process.execSync and https.get/fetch to collect host identity (uname, hostname/id), file descriptors, /proc/self/mountinfo, network/DNS data, process environment variables matched by the pattern (KEY|TOKEN|SECRET|AUTH|...), and the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, posting each result to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The same load-time code probes container-escape primitives via unshare --user --mount with devtmpfs/cgroup/release_agent mounts and a perl memfd_create+exec sequence, and ships a registry-manifest.min.json that points at static.parastorage.com/unpkg/css-overscroll-contain@1.0.1/ so the package resolves inside Wix thunderbolt build infrastructure. The declared package purpose, the Wix-internal export names, the attacker endpoint, and the credential-grade data flow are all incompatible with a legitimate CSS utility.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021238",
"import_time": "2026-10-08T21:42:55.420725689Z",
"modified_time": "2026-10-08T21:19:35Z",
"sha256": "5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-021237",
"import_time": "2026-10-08T21:42:55.316485381Z",
"modified_time": "2026-10-08T21:19:28Z",
"sha256": "b52a74f79ae282ee490c5011d4919480fccd55c1e83d1e52b15020a32da34dc6",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-021235",
"import_time": "2026-10-08T21:42:55.126202656Z",
"modified_time": "2026-10-08T21:19:11Z",
"sha256": "d51077106ae3eee19a2858b1476f3c72b2c6bf678d14e50c85441160ba13dde8",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "0bebf66b8f89240b99cbe6dadc92023156e6155740e272d3e7a43aa138b8b675",
"tlsh": "2de1a5a474ece41071a334b4bbbfa44bbbb798171d69b99070c485b41fb00bc51a9df6"
}
],
"package_integrity": [
{
"filename": "css-overscroll-contain-1.0.1.tgz",
"hashes": {
"sha1": "a72a1a6f95a84bc091063dc866ea2239f2a2358a",
"sha512_sri": "sha512-oV6aW5NyUkBtWV715bXq8DPtL4eX3BZ6IqmL7xPCy9OAkvReC8ZIcF4ey1wTr6CLqBR8gLVwEBSJCqgc16kBaw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-overscroll-contain/MAL-2026-17705.json"