-= Per source details. Do not edit below this line.=-
thunderboltRegistry.js runs an immediately-invoked function at module load that uses child_process.execSync to run host reconnaissance commands (whoami, id, pwd, ifconfig, ip addr, cat /etc/hosts, hostname) and transmits each command's output, along with Node version, platform, and pid, via fetch GET requests to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. The package also structurally impersonates Wix internal registry modules by exporting factories keyed on thunderboltRegistry/siteAssetsRegistry/documentManagementRegistry/editorRegistry/corvidRegistry and shipping a manifest with static.parastorage.com unpkg URLs under dom-focus-sentinel@1.0.0, so the exfiltration IIFE fires whenever a consumer requires any of these registry names. The reconnaissance behavior is unrelated to the declared focus-sentinel purpose, and a beacon=rce-poc marker is embedded in the exfil traffic.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020975",
"import_time": "2026-10-04T23:40:47.576741398Z",
"modified_time": "2026-10-04T23:28:40Z",
"sha256": "7baf5178b3cd02ae8e6e2c01e8cf305fd9670118428c4d3ef94ac0caef6fc4e8",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "thunderboltRegistry.js",
"sha256": "c5823a5b4efa046453d6cc532602f7dd9efa1c7a35fc5585cfcab17bcef75cbd",
"tlsh": "4f7143a5b99df02196c37438cf7f904ea4bb86672c2caee4744859b01f3945c01ba5f4"
}
],
"package_integrity": [
{
"filename": "dom-focus-sentinel-1.0.0.tgz",
"hashes": {
"sha1": "0a924b42e3d9a3f7c7234ac65964a1eef026ebda",
"sha512_sri": "sha512-vnzYiikcSu2Fg4N7IibrKCjXbbPeyGjb6ddx4LW4bgXzgxBuSFrSedz60m1UKt3tX0dLah/SQsq28C9TnDprtQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dom-focus-sentinel/MAL-2026-17503.json"