VDB
GCVE-110-OSM-2026-13217
GCVE-110-OSM-2026-13217
Advisory PublishedCVSS 5.4/10
Despite being advertised as a WCAG contrast checker, the package executes a self-invoking function at module load that runs host reconnaissance commands (whoami, id, hostname, uname -a, ls -la /, pwd, cat /etc/os-release) and collects filtered environment variables, then exfiltrates the results via DNS subdomain requests to davdpb8lhot13kgmnhp0863x9g83mpswq.oast.live and HTTP GET parameters to webhook.site/0492a36c-4d7b-408a-865c-226db25987ba. The exfiltration fires on any import of the package. Additionally, the module exports factories named after Wix Thunderbolt internal registries (thunderboltRegistry, siteAssetsRegistry, editorRegistry, corvidRegistry) and ships a registry-manifest.min.json pointing at static.parastorage.com/unpkg/minimal-a11y-contrast-check@1.0.0, impersonating internal Wix build infrastructure to be resolved via dependency confusion. A hardcoded 'internetbrands' tag embedded in the exfiltration payload indicates targeted reconnaissance.
ENTRY
index.js (main: index.js)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in thunderboltRegistry.js: ".oast.live"
- Data Encoding for Exfiltration in thunderboltRegistry.js: "encodeURIComponent(whoami"
- Network Request in thunderboltRegistry.js: "fetch("https:"
- System Information Collection in thunderboltRegistry.js: "process.platform"
ADDITIONAL FINDINGS
- Shell Command Execution in thunderboltRegistry.js: "require("child_process")"
- Very New NPM Publisher Account
PAYLOAD FILES
thunderboltRegistry.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | minimal-a11y-contrast-check | all (affected) | — |
Aliases
Browse GCVE Records
3,142 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.