OpenSSF/OSV advisory MAL-2026-17530 confirms this npm version as malicious. Package is advertised as a WCAG color accessibility helper library but ships thunderboltRegistry.js, an IIFE that on module load executes shell commands (whoami, id, pwd, ifconfig/ip addr, hostname) and transmits the output via HTTP GET and DNS subdomain lookups to the hardcoded Burp Collaborator host gzjsunzfc6i9od2ouhb6dl4a61cs0qof.oastify.com, along with node/platform/pid metadata and an 'rce-poc' beacon string...
This report applies to wcag-color-a11y-helpers@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.