-= Per source details. Do not edit below this line.=-
Despite being advertised as a WCAG contrast checker, the package executes a self-invoking function at module load that runs host reconnaissance commands (whoami, id, hostname, uname -a, ls -la /, pwd, cat /etc/os-release) and collects filtered environment variables, then exfiltrates the results via DNS subdomain requests to davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and HTTP GET parameters to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The exfiltration fires on any import of the package. Additionally, the module exports factories named after Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com/unpkg/minimal-a11y-contrast-check@1.0.0, impersonating internal Wix build infrastructure to be resolved via dependency confusion. A hardcoded 'internetbrands' tag embedded in the exfiltration payload indicates targeted reconnaissance.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020964",
"import_time": "2026-10-04T23:40:46.453629797Z",
"modified_time": "2026-10-04T23:27:03Z",
"sha256": "d9a198e6fb2c5e31bc841ff12f210e630abe8629853faf4ea961a124a9be8a25",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "edf9b93c46b444c909af166b845e231d5b9a92375c05dc573fea833409b9f11b",
"tlsh": "1bb11565ea5db06099d334389fbf900da0bb864b2d58eee4780d9ab01f75428017e6f5"
}
],
"package_integrity": [
{
"filename": "minimal-a11y-contrast-check-1.0.0.tgz",
"hashes": {
"sha1": "70a45c58c317d20f29517fc7b379bacb88b417c3",
"sha512_sri": "sha512-lAHSPTelDM3xhc2Ixc+FVkWIKyLSQNKn/QDn2S+kw+NzkFB7tGvGGUAlALgROcyhAs+f61TBYbrJMKT9E0DngA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/minimal-a11y-contrast-check/MAL-2026-17514.json"