MAL-2026-17526

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-dom-focus-trap/MAL-2026-17526.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17526
Published
2026-10-04T23:25:21Z
Modified
2026-10-04T23:45:23Z
Summary
Malicious code in tiny-dom-focus-trap (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (84262096595a1e0ce09bbaa359930cd07cf420cc72545174ddc4f12c60bec962)

The package is advertised as a focus-trap utility but thunderboltRegistry.js runs an IIFE at require time that uses child_process.execSync to run whoami, id, pwd, ifconfig / ip addr, hostname, and to read /etc/hosts, then sends each command's output as query parameters to http://dxpoc.gt.tc/callback.php via fetch. A separate beacon containing Node version, platform, and pid is also posted to the same endpoint. The package additionally impersonates Wix 'thunderbolt' internal registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry) and references static.parastorage.com manifest URLs, matching a dependency-confusion lure aimed at Wix build environments. Installing or importing this package causes the installer host's identity, network configuration, and /etc/hosts contents to be sent to an attacker-controlled host.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020953",
            "import_time":  "2026-10-04T23:40:45.41851553Z",
            "modified_time":  "2026-10-04T23:25:21Z",
            "sha256":  "84262096595a1e0ce09bbaa359930cd07cf420cc72545174ddc4f12c60bec962",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / tiny-dom-focus-trap

Package

Name
tiny-dom-focus-trap
View open source insights on deps.dev
Purl
pkg:npm/tiny-dom-focus-trap

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "3fe9351bc358c4327ec9a7ea3439385414349a425f8db5e01caed9666bb0940b",
            "tlsh":  "9f6142a5b99df02196c37438cf7f804ee4bb8a672c2caee4744899b01f3945c01ba5f5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "tiny-dom-focus-trap-1.0.0.tgz",
            "hashes":  {
                "sha1":  "3025e624b3944ccbf35e50d42f1aab4595665dec",
                "sha512_sri":  "sha512-gRrfXb5r0CmaWFk3jT5MCHjGhiXfjct/wR7cKmaht7aQKvaL85ujQiljSyf1a2pL7uXQw4vnW8bI+E/mVwMbOQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-dom-focus-trap/MAL-2026-17526.json"