MAL-2026-17705

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-overscroll-contain/MAL-2026-17705.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17705
Published
2026-10-08T21:19:11Z
Modified
2026-10-08T21:45:48Z
Summary
Malicious code in css-overscroll-contain (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16)

The package advertises itself as a CSS overscroll-behavior utility but its shipped modules (thunderboltRegistry.js and sibling files named after Wix-internal registries such as siteAssetsRegistry, editorRegistry, corvidRegistry) run a self-executing IIFE at module load that performs host reconnaissance and bulk credential theft. The IIFE uses child_process.execSync and https.get/fetch to collect host identity (uname, hostname/id), file descriptors, /proc/self/mountinfo, network/DNS data, process environment variables matched by the pattern (KEY|TOKEN|SECRET|AUTH|...), and the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, posting each result to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The same load-time code probes container-escape primitives via unshare --user --mount with devtmpfs/cgroup/release_agent mounts and a perl memfd_create+exec sequence, and ships a registry-manifest.min.json that points at static.parastorage.com/unpkg/css-overscroll-contain@1.0.1/ so the package resolves inside Wix thunderbolt build infrastructure. The declared package purpose, the Wix-internal export names, the attacker endpoint, and the credential-grade data flow are all incompatible with a legitimate CSS utility.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021238",
            "import_time": "2026-10-08T21:42:55.420725689Z",
            "modified_time": "2026-10-08T21:19:35Z",
            "sha256": "5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021237",
            "import_time": "2026-10-08T21:42:55.316485381Z",
            "modified_time": "2026-10-08T21:19:28Z",
            "sha256": "b52a74f79ae282ee490c5011d4919480fccd55c1e83d1e52b15020a32da34dc6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-021235",
            "import_time": "2026-10-08T21:42:55.126202656Z",
            "modified_time": "2026-10-08T21:19:11Z",
            "sha256": "d51077106ae3eee19a2858b1476f3c72b2c6bf678d14e50c85441160ba13dde8",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-overscroll-contain

Package

Name
css-overscroll-contain
View open source insights on deps.dev
Purl
pkg:npm/css-overscroll-contain

Affected ranges

Affected versions

1.*
1.0.1
1.0.2
1.0.3

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "thunderboltRegistry.js",
            "sha256": "0bebf66b8f89240b99cbe6dadc92023156e6155740e272d3e7a43aa138b8b675",
            "tlsh": "2de1a5a474ece41071a334b4bbbfa44bbbb798171d69b99070c485b41fb00bc51a9df6"
        }
    ],
    "package_integrity": [
        {
            "filename": "css-overscroll-contain-1.0.1.tgz",
            "hashes": {
                "sha1": "a72a1a6f95a84bc091063dc866ea2239f2a2358a",
                "sha512_sri": "sha512-oV6aW5NyUkBtWV715bXq8DPtL4eX3BZ6IqmL7xPCy9OAkvReC8ZIcF4ey1wTr6CLqBR8gLVwEBSJCqgc16kBaw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-overscroll-contain/MAL-2026-17705.json"