{"id":"MAL-2026-17705","summary":"Malicious code in css-overscroll-contain (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16)\nThe package advertises itself as a CSS overscroll-behavior utility but its shipped modules (thunderboltRegistry.js and sibling files named after Wix-internal registries such as siteAssetsRegistry, editorRegistry, corvidRegistry) run a self-executing IIFE at module load that performs host reconnaissance and bulk credential theft. The IIFE uses child_process.execSync and https.get/fetch to collect host identity (uname, hostname/id), file descriptors, /proc/self/mountinfo, network/DNS data, process environment variables matched by the pattern (KEY|TOKEN|SECRET|AUTH|...), and the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, posting each result to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The same load-time code probes container-escape primitives via unshare --user --mount with devtmpfs/cgroup/release_agent mounts and a perl memfd_create+exec sequence, and ships a registry-manifest.min.json that points at static.parastorage.com/unpkg/css-overscroll-contain@1.0.1/ so the package resolves inside Wix thunderbolt build infrastructure. The declared package purpose, the Wix-internal export names, the attacker endpoint, and the credential-grade data flow are all incompatible with a legitimate CSS utility.\n","modified":"2026-10-08T21:45:48.346686720Z","published":"2026-10-08T21:19:11Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-021238","import_time":"2026-10-08T21:42:55.420725689Z","modified_time":"2026-10-08T21:19:35Z","sha256":"5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16"},{"sha256":"b52a74f79ae282ee490c5011d4919480fccd55c1e83d1e52b15020a32da34dc6","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-021237","import_time":"2026-10-08T21:42:55.316485381Z","modified_time":"2026-10-08T21:19:28Z"},{"versions":["1.0.3"],"id":"IN-MAL-2026-021235","import_time":"2026-10-08T21:42:55.126202656Z","modified_time":"2026-10-08T21:19:11Z","sha256":"d51077106ae3eee19a2858b1476f3c72b2c6bf678d14e50c85441160ba13dde8","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-overscroll-contain/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-overscroll-contain/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-overscroll-contain/v/1.0.3"}],"affected":[{"package":{"name":"css-overscroll-contain","ecosystem":"npm","purl":"pkg:npm/css-overscroll-contain"},"versions":["1.0.1","1.0.2","1.0.3"],"database_specific":{"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"0bebf66b8f89240b99cbe6dadc92023156e6155740e272d3e7a43aa138b8b675","tlsh":"2de1a5a474ece41071a334b4bbbfa44bbbb798171d69b99070c485b41fb00bc51a9df6"}],"package_integrity":[{"hashes":{"sha1":"a72a1a6f95a84bc091063dc866ea2239f2a2358a","sha512_sri":"sha512-oV6aW5NyUkBtWV715bXq8DPtL4eX3BZ6IqmL7xPCy9OAkvReC8ZIcF4ey1wTr6CLqBR8gLVwEBSJCqgc16kBaw=="},"filename":"css-overscroll-contain-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-overscroll-contain/MAL-2026-17705.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}