VYPR

npm · Malicious package advisory

Malware

rgx33-css-grid-utils

GHSA-fqp7-jcwh-2jp3

Malicious code in rgx33-css-grid-utils (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5)
The package is published as `rgx33-css-grid-utils` but exports a set of module keys matching Wix thunderbolt internal registries (`thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, `dataBindingRegistry`, `documentManagementRegistry`, and others) — a dependency-confusion lure targeting Wix's internal build/runtime namespace. On module load, an IIFE collects host identifiers (hostname, pid, Node version, platform) and runs `child_process.execSync('id')` and `child_process.execSync('uname -r')` to capture the current user and kernel version. These values are encoded as DNS subdomain labels and sent via `fetch` to the interactsh/OOB collector `davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live`, and in parallel to `https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba` with a `where=wix-blog` query parameter identifying the campaign target. The package ships no CSS grid functionality consistent with its name; the reconnaissance beacon is the entire payload.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/rgx33-css-grid-utils/MAL-2026-17520.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/rgx33-css-grid-utils/MAL-2026-17520.json
- https://www.npmjs.com/package/rgx33-css-grid-utils/v/1.0.0
- https://github.com/advisories/GHSA-fqp7-jcwh-2jp3

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.