{"id":"MAL-2026-17521","summary":"Malicious code in rgx33-flex-layout-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb)\nPackage name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes `id` and `uname -r` via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape.\n","modified":"2026-10-04T23:45:19.007213222Z","published":"2026-10-04T23:25:38Z","database_specific":{"malicious-packages-origins":[{"sha256":"02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020955","import_time":"2026-10-04T23:40:45.602923664Z","modified_time":"2026-10-04T23:25:38Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/rgx33-flex-layout-core/v/1.0.0"}],"affected":[{"package":{"name":"rgx33-flex-layout-core","ecosystem":"npm","purl":"pkg:npm/rgx33-flex-layout-core"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rgx33-flex-layout-core/MAL-2026-17521.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"32c55be50d08a10f5ca4ddd2a589076d60660f4f2fa50ae37a79e82ed7734531","tlsh":"cf51f5da78daf00193c274758dbf9045f07bed572978af88b80895b02f7246c107aaf8"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-WmcB0SObQ5nXHOVujReRu5vAlqbMFH6lHy5SK4Yxt/vcm7znjgyMHx4t34pqiieS8GIwXVHBO6EgX50wH1HFcw==","sha1":"e08058ae389de6d4860841fe5dd2f2be97abda36"},"filename":"rgx33-flex-layout-core-1.0.0.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}