{"id":"MAL-2026-17520","summary":"Malicious code in rgx33-css-grid-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5)\nThe package is published as `rgx33-css-grid-utils` but exports a set of module keys matching Wix thunderbolt internal registries (`thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, `dataBindingRegistry`, `documentManagementRegistry`, and others) — a dependency-confusion lure targeting Wix's internal build/runtime namespace. On module load, an IIFE collects host identifiers (hostname, pid, Node version, platform) and runs `child_process.execSync('id')` and `child_process.execSync('uname -r')` to capture the current user and kernel version. These values are encoded as DNS subdomain labels and sent via `fetch` to the interactsh/OOB collector `davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live`, and in parallel to `https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba` with a `where=wix-blog` query parameter identifying the campaign target. The package ships no CSS grid functionality consistent with its name; the reconnaissance beacon is the entire payload.\n","modified":"2026-10-04T23:45:18.108869362Z","published":"2026-10-04T23:26:04Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020958","import_time":"2026-10-04T23:40:45.887559116Z","modified_time":"2026-10-04T23:26:04Z","sha256":"320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/rgx33-css-grid-utils/v/1.0.0"}],"affected":[{"package":{"name":"rgx33-css-grid-utils","ecosystem":"npm","purl":"pkg:npm/rgx33-css-grid-utils"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"b17cbd0463d9833f1510f074c8c5c7e2bcd4d43a7fcf957c779cf696b7e0b9a2","tlsh":"6651f5da78def00193c274758dbf9045f07be9572978ab98b80895b02f7146c107aaf8"}],"package_integrity":[{"hashes":{"sha1":"40e95d482c657afdf564d3b2bf5fc4f9add5953c","sha512_sri":"sha512-UXQdLsdvq8JT1cIFFmTlbmpeDNG5mC8E9hiQKiwYaBvZvvr6of4uXJKWiWhGkXLdVzP/E2peqCCGOAz78bjW2Q=="},"filename":"rgx33-css-grid-utils-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-css-grid-utils/MAL-2026-17520.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}