npm · Malicious package advisory
Malwarecss-relative-color-util
MAL-2026-17484
Malicious code in css-relative-color-util (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ee0efef48c7d56201a037b237f11ec712853f86e74f6a00ef8011732b31363f1)
The package name advertises a CSS utility, but thunderboltRegistry.js runs an IIFE on module load that uses child_process.execSync to execute whoami, uname -a, cat /etc/hosts, and ifconfig/ip addr, then exfiltrates the output together with os.hostname and the Node version to a hardcoded webhook at https://dxpoc.gt.tc/callback.php/ via fetch and to an *.oast.live DNS collector via dns.resolve. The loader deletes any require.cache entry containing 'thunderboltRegistry' so the IIFE re-fires on subsequent requires, and falls back to node:child_process and new module.constructor().require('child_process') to obtain the exec primitive. The package also exports stubs named thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry and similar, matching internal Wix thunderbolt module names, with a registry-manifest.min.json pointing at static.parastorage.com unpkg paths — a dependency-confusion shape targeting an internal namespace. The declared CSS-utility purpose is unrelated to any of this behavior.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.