css-flow-render-shim@1.0.0
Malicious code in css-flow-render-shim (npm)
Analysis
css-flow-render-shim@1.0.0 ships a bundled payload (package/payload.bundle.min.js) that executes when the module is required. It first deletes matching entries from require.cache (paths containing "payload", "rb_wixui", "rb_dsgnsys") to conceal its presence, then collects host reconnaissance by spawning child processes: whoami, id, uname -a, `env | head -100`, ifconfig / ip addr, and `cat /etc/hosts`. Each command's output is sent as a query string to the hardcoded collector hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (via fetch() with an https.get() fallback), together with the hostname, Node version, platform, pid and the package name. The environment dump can carry credentials and tokens present in the installer's environment. The remainder of the file is a Proxy-based stub exporting fake Wix thunderbolt registry names (thunderboltRegistry, corvidRegistry, editorRegistry, etc.) to make the package resemble a CSS/render shim; the declared entry point index.js is an empty module, so the payload is reached by requiring payload.bundle.min.js directly. IOCs: C2 hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418 (host webhook[.]site, port 443).
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 12:01 AM
- analyzed
- Oct 7, 2026, 12:01 AM
Related advisories
- css-reading-display-polyfill@1.0.0
- css-jptvix-polyfill@1.0.0
- @worrisome/aaaa@1.0.0
- unreal-horde-dashboard@99999.0.0
- hyperpure@1.0.0
- zomato-server@1.0.0
- hex-conv-ae7a@1.0.0
- vaults-monitor-cron@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.