VYPR

npm · Malicious package advisory

Malware

rgx33-css-grid-utils

MAL-2026-17520

Malicious code in rgx33-css-grid-utils (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (320488b79c9000782e398425aa1a2fddba7f29a487913bbb2fc2019405c078f5)
The package is published as `rgx33-css-grid-utils` but exports a set of module keys matching Wix thunderbolt internal registries (`thunderboltRegistry`, `siteAssetsRegistry`, `editorRegistry`, `corvidRegistry`, `dataBindingRegistry`, `documentManagementRegistry`, and others) — a dependency-confusion lure targeting Wix's internal build/runtime namespace. On module load, an IIFE collects host identifiers (hostname, pid, Node version, platform) and runs `child_process.execSync('id')` and `child_process.execSync('uname -r')` to capture the current user and kernel version. These values are encoded as DNS subdomain labels and sent via `fetch` to the interactsh/OOB collector `davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live`, and in parallel to `https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba` with a `where=wix-blog` query parameter identifying the campaign target. The package ships no CSS grid functionality consistent with its name; the reconnaissance beacon is the entire payload.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.