Logo
npm

css-a11y-contrast-utils@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17475

Ecosystem

npm

Summary

css-a11y-contrast-utils@1.0.0 is advertised as a WCAG contrast utility but ships no contrast code — index.js exports an empty object. The package instead defines a Proxy stub exposing identifiers from Wix's internal Thunderbolt registry namespace (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry, etc.), and its manifest points at static.parastorage.com/unpkg/css-a11y-contrast-utils, consistent with a dependency-confusion squat targeting a private Wix registry. On module load, thunderboltRegistry.js runs an IIFE that executes hostname, id, and uname -r via child_process and exfiltrates the collected host, uid, kernel version, Node version, and pid by (a) issuing DNS lookups to subdomains of the hardcoded OAST collector davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and (b) HTTP GET to the hardcoded webhook https://webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The cover-story metadata plus internal-registry naming plus the on-load recon beacon make the entire purpose of the package a dependency-confusion payload against installers that resolve any of these registry names.

Source: amazon-inspector (85ad65ab7d49c4277898f5da5b5d45f3ec9cde46035bcf6416e3a95507ca1301)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.