postcss-gap-fallback-util@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17518
Ecosystem
npm
Summary
The package is published as a PostCSS gap fallback utility but ships thunderboltRegistry.js, which executes an IIFE on module load. The IIFE runs whoami, id, and hostname via child_process.execSync, curls the AWS instance metadata service at http://169.254.169.254/latest/meta-data/ for IAM role, instance-id, availability zone, and local IPv4, and sends the results to https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba along with DNS beacons to a host under oast.live. A registry-manifest.min.json maps multiple Wix-internal registry names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry) to the same exfiltration file, and the module exports a Proxy returning no-op registry methods as a façade. The naming, manifest, and façade indicate a dependency-confusion payload targeting Wix build infrastructure; on any installer that requires one of the impersonated module names, shell identity, hostname, and (on EC2) AWS IAM role credentials/metadata are leaked to an attacker-controlled webhook and DNS collector.
Source: amazon-inspector (5b54d5bd893bc377a77503059998e01ae3e338fd4d8ddac6fe2d7c71a3157cb5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.