{"id":"MAL-2026-17514","summary":"Malicious code in minimal-a11y-contrast-check (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d9a198e6fb2c5e31bc841ff12f210e630abe8629853faf4ea961a124a9be8a25)\nDespite being advertised as a WCAG contrast checker, the package executes a self-invoking function at module load that runs host reconnaissance commands (whoami, id, hostname, uname -a, ls -la /, pwd, cat /etc/os-release) and collects filtered environment variables, then exfiltrates the results via DNS subdomain requests to davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and HTTP GET parameters to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The exfiltration fires on any import of the package. Additionally, the module exports factories named after Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com/unpkg/minimal-a11y-contrast-check@1.0.0, impersonating internal Wix build infrastructure to be resolved via dependency confusion. A hardcoded 'internetbrands' tag embedded in the exfiltration payload indicates targeted reconnaissance.\n","modified":"2026-10-04T23:45:21.064382132Z","published":"2026-10-04T23:27:03Z","database_specific":{"malicious-packages-origins":[{"sha256":"d9a198e6fb2c5e31bc841ff12f210e630abe8629853faf4ea961a124a9be8a25","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020964","import_time":"2026-10-04T23:40:46.453629797Z","modified_time":"2026-10-04T23:27:03Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/minimal-a11y-contrast-check/v/1.0.0"}],"affected":[{"package":{"name":"minimal-a11y-contrast-check","ecosystem":"npm","purl":"pkg:npm/minimal-a11y-contrast-check"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"edf9b93c46b444c909af166b845e231d5b9a92375c05dc573fea833409b9f11b","tlsh":"1bb11565ea5db06099d334389fbf900da0bb864b2d58eee4780d9ab01f75428017e6f5","path":"thunderboltRegistry.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-lAHSPTelDM3xhc2Ixc+FVkWIKyLSQNKn/QDn2S+kw+NzkFB7tGvGGUAlALgROcyhAs+f61TBYbrJMKT9E0DngA==","sha1":"70a45c58c317d20f29517fc7b379bacb88b417c3"},"filename":"minimal-a11y-contrast-check-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/minimal-a11y-contrast-check/MAL-2026-17514.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}