LWA-2026-12710 confirmed malware

css-overscroll-contain@1.0.3

Malicious code in css-overscroll-contain (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1036 · MasqueradingT1552 · Unsecured CredentialsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1057 · Process DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

css-overscroll-contain@1.0.3 presents itself as a CSS overscroll-behavior polyfill, but its declared entry point index.js is an empty stub (module.exports={}) and package.json declares no scripts, bin entries, or dependencies. The tarball instead ships package/thunderboltRegistry.js, a 5.8 KB payload that executes as soon as the module is loaded. It requires child_process, runs shell commands through execSync, and posts the results as HTTP GET requests to hxxps://webhook[.]site/4a7272ce-00ca-48b2-904a-05679b11493b, tagging each request (?tag=info, mknod, fds, mounts, memfd, symlink, kernel, env, procs, done) and truncating the body to 3000 characters. Collected data includes `id`, `uname -a`, the Node version and PID; a /proc/self/fd listing with socket peer credentials; /proc/self/status capability and seccomp flags; namespace listings; and a process list read from a procfs mount. It also harvests credentials by running `env | grep -iE '(key|token|secret|pass|auth|host|port|url|endpoint|service|kube)'` and sending the output to the same endpoint. It then probes for container/sandbox escape: mknod of cuse/fuse/null device nodes via syscall 259 (referenced in the code as CVE-2026-96812), memfd_create (syscall 319) followed by execution of /proc/self/fd, symlink traversal to /proc/1/root, and unshare --user --mount --map-root-user mount attempts of proc, sysfs, tmpfs, devtmpfs, devpts, cgroup, cgroup2, fusectl and overlay. The remainder of the file exports Proxy stubs named thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry and similar, mimicking a component-registry module so the file resembles ordinary library code.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 06:32 PM
analyzed
Oct 8, 2026, 06:33 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.