Logo
npm

tiny-css-token-parser@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17525

Ecosystem

npm

Summary

Package is advertised as a CSS token parser but ships thunderboltRegistry.js which runs an IIFE on module load that collects hostname, pid, Node version, platform, and the output of id and uname -r via child_process.execSync, then exfiltrates them as DNS/HTTP subdomains under an oast.live interact.sh collector and a POST to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba with a where=internetbrands tag. The package manifest aliases seven internal Wix Thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) to the same recon module and exports factories under those keys, so any loader that resolves those internal names to this public package will execute the recon payload. The name/description are a cover story; the actual behavior is targeted dependency-confusion reconnaissance against Wix's internetbrands build graph.

Source: amazon-inspector (ee63fae51fceee7c4d3c5051e191e477ca9bb8302f6fc4d3d07f5446951efa0f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.