Logo
npm

css-relative-color-util@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17484

Ecosystem

npm

Summary

The package name advertises a CSS utility, but thunderboltRegistry.js runs an IIFE on module load that uses child_process.execSync to execute whoami, uname -a, cat /etc/hosts, and ifconfig/ip addr, then exfiltrates the output together with os.hostname and the Node version to a hardcoded webhook at https://dxpoc.gt.tc/callback.php/ via fetch and to an *.oast.live DNS collector via dns.resolve. The loader deletes any require.cache entry containing 'thunderboltRegistry' so the IIFE re-fires on subsequent requires, and falls back to node:child_process and new module.constructor().require('child_process') to obtain the exec primitive. The package also exports stubs named thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry and similar, matching internal Wix thunderbolt module names, with a registry-manifest.min.json pointing at static.parastorage.com unpkg paths — a dependency-confusion shape targeting an internal namespace. The declared CSS-utility purpose is unrelated to any of this behavior.

Source: amazon-inspector (ee0efef48c7d56201a037b237f11ec712853f86e74f6a00ef8011732b31363f1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.