MAL-2026-17530

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wcag-color-a11y-helpers/MAL-2026-17530.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17530
Published
2026-10-04T23:24:49Z
Modified
2026-10-04T23:45:23Z
Summary
Malicious code in wcag-color-a11y-helpers (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8b6e72298f32298d6558f5d52eb7a9d5185b37fe8df14748bf61d6686dde1cb3)

Package is advertised as a WCAG color accessibility helper library but ships thunderboltRegistry.js, an IIFE that on module load executes shell commands (whoami, id, pwd, ifconfig/ip addr, hostname) and transmits the output via HTTP GET and DNS subdomain lookups to the hardcoded Burp Collaborator host gzjsunzfc6i9od2ouhb6dl4a61cs0qof.oastify.com, along with node/platform/pid metadata and an 'rce-poc' beacon string. The package exports factory functions under names mirroring Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry), and ships a registry-manifest.min.json that maps all of those registry names to thunderboltRegistry.js — a dependency-confusion/typosquat shape against Wix's @wix/thunderbolt-* internal registries. Any consumer that resolves one of these names loads and executes the recon/exfiltration payload. The a11y naming is a cover story unrelated to the actual code.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020950",
            "import_time":  "2026-10-04T23:40:45.15225788Z",
            "modified_time":  "2026-10-04T23:24:49Z",
            "sha256":  "8b6e72298f32298d6558f5d52eb7a9d5185b37fe8df14748bf61d6686dde1cb3",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / wcag-color-a11y-helpers

Package

Name
wcag-color-a11y-helpers
View open source insights on deps.dev
Purl
pkg:npm/wcag-color-a11y-helpers

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "55050aacbdcbdd3269e1eb7f379655dd0296a024bac20216d56ab1d5f4e7a9a4",
            "tlsh":  "0d8123aab95eb06155c33838cbbf5049f4b786532c1caee0784855f01f7446c11beaf5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "wcag-color-a11y-helpers-1.0.0.tgz",
            "hashes":  {
                "sha1":  "26e21ba3c3614547119632027d5b533903c123f8",
                "sha512_sri":  "sha512-rz05/Y4aw7r1poQZYYV3c3cvL1GY5cBZ5NjKOHe1GYls0BGf9cm6aolKE/v/nEAzvnLTagmd6nJ8EzdKhFN5DQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wcag-color-a11y-helpers/MAL-2026-17530.json"