MAL-2026-17475

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-a11y-contrast-utils/MAL-2026-17475.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17475
Published
2026-10-04T23:13:28Z
Modified
2026-10-04T23:30:05Z
Summary
Malicious code in css-a11y-contrast-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (85ad65ab7d49c4277898f5da5b5d45f3ec9cde46035bcf6416e3a95507ca1301)

css-a11y-contrast-utils@1.0.0 is advertised as a WCAG contrast utility but ships no contrast code — index.js exports an empty object. The package instead defines a Proxy stub exposing identifiers from Wix's internal Thunderbolt registry namespace (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), and its manifest points at static.parastorage.com/unpkg/css-a11y-contrast-utils, consistent with a dependency-confusion squat targeting a private Wix registry. On module load, thunderboltRegistry.js runs an IIFE that executes hostname, id, and uname -r via child_process and exfiltrates the collected host, uid, kernel version, Node version, and pid by (a) issuing DNS lookups to subdomains of the hardcoded OAST collector davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and (b) HTTP GET to the hardcoded webhook https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The cover-story metadata plus internal-registry naming plus the on-load recon beacon make the entire purpose of the package a dependency-confusion payload against installers that resolve any of these registry names.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020881",
            "import_time":  "2026-10-04T23:16:30.144371793Z",
            "modified_time":  "2026-10-04T23:13:28Z",
            "sha256":  "85ad65ab7d49c4277898f5da5b5d45f3ec9cde46035bcf6416e3a95507ca1301",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / css-a11y-contrast-utils

Package

Name
css-a11y-contrast-utils
View open source insights on deps.dev
Purl
pkg:npm/css-a11y-contrast-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "fd6c8d81e78e4679fffb54a2708bc42b4f0333a7596dd0d06ac87a52af659e21",
            "tlsh":  "e661245ab99ef00086c37438df7f904da4fba9532d686ad4780495f02f7586c10ba9f9"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "css-a11y-contrast-utils-1.0.0.tgz",
            "hashes":  {
                "sha1":  "0e6004d847a2b7c8a720fbc3db2440d85aaffa72",
                "sha512_sri":  "sha512-c4lqiC1JdJx82wb3N7N+dkh/mdRuu0Y0od9U5OtlpWQXp7Ur5pbVRaRz0cotipWxHMJ0ZVULcxBl+iWFZQsKtw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-a11y-contrast-utils/MAL-2026-17475.json"