npm · Malicious package advisory
Malwarecss-relative-color-util
GHSA-63h7-vcf3-9xgh
Malicious code in css-relative-color-util (npm)
Details
**Severity:** Critical
**Affected versions:** `= 1.0.0`
## Source: amazon-inspector (ee0efef48c7d56201a037b237f11ec712853f86e74f6a00ef8011732b31363f1)
The package name advertises a CSS utility, but thunderboltRegistry.js runs an IIFE on module load that uses child_process.execSync to execute whoami, uname -a, cat /etc/hosts, and ifconfig/ip addr, then exfiltrates the output together with os.hostname and the Node version to a hardcoded webhook at https://dxpoc.gt.tc/callback.php/ via fetch and to an *.oast.live DNS collector via dns.resolve. The loader deletes any require.cache entry containing 'thunderboltRegistry' so the IIFE re-fires on subsequent requires, and falls back to node:child_process and new module.constructor().require('child_process') to obtain the exec primitive. The package also exports stubs named thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry and similar, matching internal Wix thunderbolt module names, with a registry-manifest.min.json pointing at static.parastorage.com unpkg paths — a dependency-confusion shape targeting an internal namespace. The declared CSS-utility purpose is unrelated to any of this behavior.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-relative-color-util/MAL-2026-17484.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/css-relative-color-util/MAL-2026-17484.json
- https://www.npmjs.com/package/css-relative-color-util/v/1.0.0
- https://github.com/advisories/GHSA-63h7-vcf3-9xghCompromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.