{"id":"MAL-2026-17530","summary":"Malicious code in wcag-color-a11y-helpers (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8b6e72298f32298d6558f5d52eb7a9d5185b37fe8df14748bf61d6686dde1cb3)\nPackage is advertised as a WCAG color accessibility helper library but ships thunderboltRegistry.js, an IIFE that on module load executes shell commands (whoami, id, pwd, ifconfig/ip addr, hostname) and transmits the output via HTTP GET and DNS subdomain lookups to the hardcoded Burp Collaborator host gzjsunzfc6i9od2ouhb6dl4a61cs0qof.oastify.com, along with node/platform/pid metadata and an 'rce-poc' beacon string. The package exports factory functions under names mirroring Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, dataBindingRegistry, autoCompleteRegistry, thunderboltBuilderRegistry, thunderboltPreviewRegistry), and ships a registry-manifest.min.json that maps all of those registry names to thunderboltRegistry.js — a dependency-confusion/typosquat shape against Wix's @wix/thunderbolt-* internal registries. Any consumer that resolves one of these names loads and executes the recon/exfiltration payload. The a11y naming is a cover story unrelated to the actual code.\n","modified":"2026-10-04T23:45:23.861238441Z","published":"2026-10-04T23:24:49Z","database_specific":{"malicious-packages-origins":[{"sha256":"8b6e72298f32298d6558f5d52eb7a9d5185b37fe8df14748bf61d6686dde1cb3","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020950","import_time":"2026-10-04T23:40:45.15225788Z","modified_time":"2026-10-04T23:24:49Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wcag-color-a11y-helpers/v/1.0.0"}],"affected":[{"package":{"name":"wcag-color-a11y-helpers","ecosystem":"npm","purl":"pkg:npm/wcag-color-a11y-helpers"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"55050aacbdcbdd3269e1eb7f379655dd0296a024bac20216d56ab1d5f4e7a9a4","tlsh":"0d8123aab95eb06155c33838cbbf5049f4b786532c1caee0784855f01f7446c11beaf5"}],"package_integrity":[{"hashes":{"sha1":"26e21ba3c3614547119632027d5b533903c123f8","sha512_sri":"sha512-rz05/Y4aw7r1poQZYYV3c3cvL1GY5cBZ5NjKOHe1GYls0BGf9cm6aolKE/v/nEAzvnLTagmd6nJ8EzdKhFN5DQ=="},"filename":"wcag-color-a11y-helpers-1.0.0.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wcag-color-a11y-helpers/MAL-2026-17530.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}