MAL-2026-17514

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/minimal-a11y-contrast-check/MAL-2026-17514.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17514
Published
2026-10-04T23:27:03Z
Modified
2026-10-04T23:45:21Z
Summary
Malicious code in minimal-a11y-contrast-check (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (d9a198e6fb2c5e31bc841ff12f210e630abe8629853faf4ea961a124a9be8a25)

Despite being advertised as a WCAG contrast checker, the package executes a self-invoking function at module load that runs host reconnaissance commands (whoami, id, hostname, uname -a, ls -la /, pwd, cat /etc/os-release) and collects filtered environment variables, then exfiltrates the results via DNS subdomain requests to davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and HTTP GET parameters to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The exfiltration fires on any import of the package. Additionally, the module exports factories named after Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com/unpkg/minimal-a11y-contrast-check@1.0.0, impersonating internal Wix build infrastructure to be resolved via dependency confusion. A hardcoded 'internetbrands' tag embedded in the exfiltration payload indicates targeted reconnaissance.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020964",
            "import_time":  "2026-10-04T23:40:46.453629797Z",
            "modified_time":  "2026-10-04T23:27:03Z",
            "sha256":  "d9a198e6fb2c5e31bc841ff12f210e630abe8629853faf4ea961a124a9be8a25",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / minimal-a11y-contrast-check

Package

Name
minimal-a11y-contrast-check
View open source insights on deps.dev
Purl
pkg:npm/minimal-a11y-contrast-check

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "edf9b93c46b444c909af166b845e231d5b9a92375c05dc573fea833409b9f11b",
            "tlsh":  "1bb11565ea5db06099d334389fbf900da0bb864b2d58eee4780d9ab01f75428017e6f5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "minimal-a11y-contrast-check-1.0.0.tgz",
            "hashes":  {
                "sha1":  "70a45c58c317d20f29517fc7b379bacb88b417c3",
                "sha512_sri":  "sha512-lAHSPTelDM3xhc2Ixc+FVkWIKyLSQNKn/QDn2S+kw+NzkFB7tGvGGUAlALgROcyhAs+f61TBYbrJMKT9E0DngA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/minimal-a11y-contrast-check/MAL-2026-17514.json"