{"id":"MAL-2026-17475","summary":"Malicious code in css-a11y-contrast-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (85ad65ab7d49c4277898f5da5b5d45f3ec9cde46035bcf6416e3a95507ca1301)\ncss-a11y-contrast-utils@1.0.0 is advertised as a WCAG contrast utility but ships no contrast code — index.js exports an empty object. The package instead defines a Proxy stub exposing identifiers from Wix's internal Thunderbolt registry namespace (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), and its manifest points at static.parastorage.com/unpkg/css-a11y-contrast-utils, consistent with a dependency-confusion squat targeting a private Wix registry. On module load, thunderboltRegistry.js runs an IIFE that executes `hostname`, `id`, and `uname -r` via child_process and exfiltrates the collected host, uid, kernel version, Node version, and pid by (a) issuing DNS lookups to subdomains of the hardcoded OAST collector davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and (b) HTTP GET to the hardcoded webhook https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The cover-story metadata plus internal-registry naming plus the on-load recon beacon make the entire purpose of the package a dependency-confusion payload against installers that resolve any of these registry names.\n","modified":"2026-10-04T23:30:05.686232777Z","published":"2026-10-04T23:13:28Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020881","import_time":"2026-10-04T23:16:30.144371793Z","modified_time":"2026-10-04T23:13:28Z","sha256":"85ad65ab7d49c4277898f5da5b5d45f3ec9cde46035bcf6416e3a95507ca1301","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-a11y-contrast-utils/v/1.0.0"}],"affected":[{"package":{"name":"css-a11y-contrast-utils","ecosystem":"npm","purl":"pkg:npm/css-a11y-contrast-utils"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"fd6c8d81e78e4679fffb54a2708bc42b4f0333a7596dd0d06ac87a52af659e21","tlsh":"e661245ab99ef00086c37438df7f904da4fba9532d686ad4780495f02f7586c10ba9f9"}],"package_integrity":[{"filename":"css-a11y-contrast-utils-1.0.0.tgz","hashes":{"sha1":"0e6004d847a2b7c8a720fbc3db2440d85aaffa72","sha512_sri":"sha512-c4lqiC1JdJx82wb3N7N+dkh/mdRuu0Y0od9U5OtlpWQXp7Ur5pbVRaRz0cotipWxHMJ0ZVULcxBl+iWFZQsKtw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-a11y-contrast-utils/MAL-2026-17475.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}