{"id":"MAL-2026-17477","summary":"Malicious code in css-env-function-shim (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (03e6fced50259d6d3781ef3917caba965e4744420188c3e06919541b64e2e294)\nPackage self-describes as a CSS env() shim but ships thunderboltRegistry.js, which runs an IIFE at module load that base64-decodes the strings 'child_process' and 'execSync', dynamically requires child_process, and shells out whoami, uname, cat /etc/hosts, ifconfig/ip addr, id, and hostname. The collected output is POSTed to a hardcoded webhook.site URL (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba) and beaconed to a subdomain of davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live for DNS exfiltration. All sensitive identifiers (module name, method name, commands, destination host, UUID path, OAST subdomain) are stored as base64 blobs or String.fromCharCode arrays and reconstructed at runtime to defeat static inspection. index.js is a stub; the module factory is re-exported under nine Wix-internal registry key names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and similar), and the shipped registry-manifest.min.json aliases numerous Wix thunderbolt *Registry.js URLs on parastorage.com to this package's thunderboltRegistry.js — a dependency-confusion lure targeting Wix's internal build so that any importer of those names triggers the exfiltration IIFE at require time.\n","modified":"2026-10-04T23:30:05.789975954Z","published":"2026-10-04T23:13:53Z","database_specific":{"malicious-packages-origins":[{"sha256":"03e6fced50259d6d3781ef3917caba965e4744420188c3e06919541b64e2e294","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020884","import_time":"2026-10-04T23:16:30.311679784Z","modified_time":"2026-10-04T23:13:53Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-env-function-shim/v/1.0.0"}],"affected":[{"package":{"name":"css-env-function-shim","ecosystem":"npm","purl":"pkg:npm/css-env-function-shim"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-env-function-shim/MAL-2026-17477.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"e3de7ea4ec468ec5f0e47c839eb7d2097c875fac37040d89901075e9e12a9fa8","tlsh":"0a8172edb9d6a0051953647987bf200b71b7daa32d68c490f89ed5f42f70228843e7f9"}],"package_integrity":[{"filename":"css-env-function-shim-1.0.0.tgz","hashes":{"sha1":"98d09e15e0a93d9d1166ed61d204f6d88a8a325e","sha512_sri":"sha512-HytTrAFrnD7uPPXmkggEqttDZNy81gBzz4dosHK0tNacsvxIHrnZgELaYyqmqeLawJG+pRRKfcelcQFesSSFEQ=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}