{"id":"MAL-2026-17525","summary":"Malicious code in tiny-css-token-parser (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f)\nPackage is advertised as a CSS token parser but ships thunderboltRegistry.js which runs an IIFE on module load that collects hostname, pid, Node version, platform, and the output of `id` and `uname -r` via child_process.execSync, then exfiltrates them as DNS/HTTP subdomains under an oast.live interact.sh collector and a POST to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a `where=internetbrands` tag. The package manifest aliases seven internal Wix Thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) to the same recon module and exports factories under those keys, so any loader that resolves those internal names to this public package will execute the recon payload. The name/description are a cover story; the actual behavior is targeted dependency-confusion reconnaissance against Wix's internetbrands build graph.\n","modified":"2026-10-04T23:45:21.772962651Z","published":"2026-10-04T23:25:27Z","database_specific":{"malicious-packages-origins":[{"sha256":"ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020954","import_time":"2026-10-04T23:40:45.509867136Z","modified_time":"2026-10-04T23:25:27Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tiny-css-token-parser/v/1.0.0"}],"affected":[{"package":{"name":"tiny-css-token-parser","ecosystem":"npm","purl":"pkg:npm/tiny-css-token-parser"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"b2e3286b25a4faf31781cf3dc94d2821df31afa4b25f3c550dc5cb699e32c8e2","tlsh":"b651f5da78daf00193c274758dbf9045f07be9572978af88b80895b02f7246c107eaf8"}],"package_integrity":[{"filename":"tiny-css-token-parser-1.0.0.tgz","hashes":{"sha512_sri":"sha512-UqOYEJzmbxTqsIw37/8MuIOze2/3p7ctUU2SapOGp9tJZdbj5TAwPu8XW5XbOVQeGeBfqbXRScd7FG/HjInuLw==","sha1":"1eb250f2ce0fc5aa80b6e88dd81d002fb214b009"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-css-token-parser/MAL-2026-17525.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}