LWA-2026-12641 confirmed malware

css-flow-render-shim@1.0.0

Malicious code in css-flow-render-shim (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1070 · Indicator Removal

Analysis

css-flow-render-shim@1.0.0 ships a bundled payload (package/payload.bundle.min.js) that executes when the module is required. It first deletes matching entries from require.cache (paths containing "payload", "rb_wixui", "rb_dsgnsys") to conceal its presence, then collects host reconnaissance by spawning child processes: whoami, id, uname -a, `env | head -100`, ifconfig / ip addr, and `cat /etc/hosts`. Each command's output is sent as a query string to the hardcoded collector hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (via fetch() with an https.get() fallback), together with the hostname, Node version, platform, pid and the package name. The environment dump can carry credentials and tokens present in the installer's environment. The remainder of the file is a Proxy-based stub exporting fake Wix thunderbolt registry names (thunderboltRegistry, corvidRegistry, editorRegistry, etc.) to make the package resemble a CSS/render shim; the declared entry point index.js is an empty module, so the payload is reached by requiring payload.bundle.min.js directly. IOCs: C2 hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (host webhook[.]site, port 443).

analyzed by
Leitwacht
first seen
Oct 7, 2026, 12:01 AM
analyzed
Oct 7, 2026, 12:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.