rgx33-flex-layout-core@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17521
Ecosystem
npm
Summary
Package name and exports (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.) impersonate internal Wix thunderbolt registry packages, targeting Wix build pipelines via dependency confusion. On require, thunderboltRegistry.js executes id and uname -r via child_process.execSync and collects hostname, pid, Node.js version, and platform. These values are encoded into subdomains of an attacker-controlled Interactsh/OAST callback domain (davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live) and also POSTed to a webhook.site collector (webhook.site/0492a36c-4d7b-408a-865c-226db25987ba). The exfiltration behavior has no relation to the package's advertised 'flexbox layout utilities' purpose, and the manifest references to static.parastorage.com paths reinforce the Wix-targeted dependency-confusion shape.
Source: amazon-inspector (02200327d66cf0661b787f58049b55b5fbb95dfb76fbb81a679cc71439bd85eb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.