Logo
npm

rgx33-flex-layout-core@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17521

Ecosystem

npm

Summary

Package name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes id and uname -r via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape.

Source: amazon-inspector (02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.