-= Per source details. Do not edit below this line.=-
Package is advertised as a WCAG color accessibility helper library but ships thunderboltRegistry.js, an IIFE that on module load executes shell commands (whoami, id, pwd, ifconfig/ip addr, hostname) and transmits the output via HTTP GET and DNS subdomain lookups to the hardcoded Burp Collaborator host gzjsunzfc6i9od2ouhb6dl4a61cs0qof.oastify.com, along with node/platform/pid metadata and an 'rce-poc' beacon string. The package exports factory functions under names mirroring Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry), and ships a registry-manifest.min.json that maps all of those registry names to thunderboltRegistry.js — a dependency-confusion/typosquat shape against Wix's @wix/thunderbolt-* internal registries. Any consumer that resolves one of these names loads and executes the recon/exfiltration payload. The a11y naming is a cover story unrelated to the actual code.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020950",
"import_time": "2026-10-04T23:40:45.15225788Z",
"modified_time": "2026-10-04T23:24:49Z",
"sha256": "8b6e72298f32298d6558f5d52eb7a9d5185b37fe8df14748bf61d6686dde1cb3",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "55050aacbdcbdd3269e1eb7f379655dd0296a024bac20216d56ab1d5f4e7a9a4",
"tlsh": "0d8123aab95eb06155c33838cbbf5049f4b786532c1caee0784855f01f7446c11beaf5"
}
],
"package_integrity": [
{
"filename": "wcag-color-a11y-helpers-1.0.0.tgz",
"hashes": {
"sha1": "26e21ba3c3614547119632027d5b533903c123f8",
"sha512_sri": "sha512-rz05/Y4aw7r1poQZYYV3c3cvL1GY5cBZ5NjKOHe1GYls0BGf9cm6aolKE/v/nEAzvnLTagmd6nJ8EzdKhFN5DQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wcag-color-a11y-helpers/MAL-2026-17530.json"