VDB

GCVE-110-OSM-2026-13217

GCVE-110-OSM-2026-13217
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 5, 2026
Despite being advertised as a WCAG contrast checker, the package executes a self-invoking function at module load that runs host reconnaissance commands (whoami, id, hostname, uname -a, ls -la /, pwd, cat /etc/os-release) and collects filtered environment variables, then exfiltrates the results via DNS subdomain requests to davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and HTTP GET parameters to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The exfiltration fires on any import of the package. Additionally, the module exports factories named after Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com/unpkg/minimal-a11y-contrast-check@1.0.0, impersonating internal Wix build infrastructure to be resolved via dependency confusion. A hardcoded 'internetbrands' tag embedded in the exfiltration payload indicates targeted reconnaissance. ENTRY index.js (main: index.js) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in thunderboltRegistry.js: ".oast.live" - Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(whoami" - Network Request in thunderboltRegistry.js: "fetch("https:" - System Information Collection in thunderboltRegistry.js: "process.platform" ADDITIONAL FINDINGS - Shell Command Execution in thunderboltRegistry.js: "require("child_process")" - Very New NPM Publisher Account PAYLOAD FILES thunderboltRegistry.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownminimal-a11y-contrast-checkall (affected)—

References

advisory
vendor

Browse GCVE Records

3,142 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›