css-overscroll-contain@1.0.3
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC
OSV ID
MAL-2026-17705
Ecosystem
npm
Summary
The package advertises itself as a CSS overscroll-behavior utility but its shipped modules (thunderboltRegistry.js and sibling files named after Wix-internal registries such as siteAssetsRegistry, editorRegistry, corvidRegistry) run a self-executing IIFE at module load that performs host reconnaissance and bulk credential theft. The IIFE uses child_process.execSync and https.get/fetch to collect host identity (uname, hostname/id), file descriptors, /proc/self/mountinfo, network/DNS data, process environment variables matched by the pattern (KEY|TOKEN|SECRET|AUTH|...), and the Kubernetes service-account token at /var/run/secrets/kubernetes.io/serviceaccount/token, posting each result to the hardcoded endpoint https://dxpoc.gt.tc/callback.php/bb8968d0f67000433bf7005dd5ad2d1f. The same load-time code probes container-escape primitives via unshare --user --mount with devtmpfs/cgroup/release_agent mounts and a perl memfd_create+exec sequence, and ships a registry-manifest.min.json that points at static.parastorage.com/unpkg/css-overscroll-contain@1.0.1/ so the package resolves inside Wix thunderbolt build infrastructure. The declared package purpose, the Wix-internal export names, the attacker endpoint, and the credential-grade data flow are all incompatible with a legitimate CSS utility.
Source: amazon-inspector (5d978121f021eb6136e6a34db790556ba757de3bb8fa81981903445baf025d16)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.