VYPR

npm · Malicious package advisory

Malware

css-env-function-shim

MAL-2026-17477

Malicious code in css-env-function-shim (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (03e6fced50259d6d3781ef3917caba965e4744420188c3e06919541b64e2e294)
Package self-describes as a CSS env() shim but ships thunderboltRegistry.js, which runs an IIFE at module load that base64-decodes the strings 'child_process' and 'execSync', dynamically requires child_process, and shells out whoami, uname, cat /etc/hosts, ifconfig/ip addr, id, and hostname. The collected output is POSTed to a hardcoded webhook.site URL (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba) and beaconed to a subdomain of davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live for DNS exfiltration. All sensitive identifiers (module name, method name, commands, destination host, UUID path, OAST subdomain) are stored as base64 blobs or String.fromCharCode arrays and reconstructed at runtime to defeat static inspection. index.js is a stub; the module factory is re-exported under nine Wix-internal registry key names (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, and similar), and the shipped registry-manifest.min.json aliases numerous Wix thunderbolt *Registry.js URLs on parastorage.com to this package's thunderboltRegistry.js — a dependency-confusion lure targeting Wix's internal build so that any importer of those names triggers the exfiltration IIFE at require time.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.