MAL-2026-17527

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-focusgroup-helper/MAL-2026-17527.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17527
Published
2026-10-04T23:24:59Z
Modified
2026-10-04T23:45:21Z
Summary
Malicious code in tiny-focusgroup-helper (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9c6d210f6c61d0ec49fac4bf487a2d71966b1f3dd59653d8a8fdf12e04f9b306)

tiny-focusgroup-helper@1.0.0 declares itself as a focus-group accessibility helper, but thunderboltRegistry.js runs an IIFE at require time that executes whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts via child_process, and POSTs/GETs the output as query parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3, along with a beacon containing node version, platform, and pid. The dxpoc.gt.tc host is a dynamic-DNS domain unrelated to any legitimate publisher. The package's exported surface (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) mirrors internal Wix thunderbolt registry module names and the shipped manifest references static.parastorage.com, consistent with a dependency-confusion/module-impersonation lure targeting Wix build environments.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020951",
            "import_time":  "2026-10-04T23:40:45.239974523Z",
            "modified_time":  "2026-10-04T23:24:59Z",
            "sha256":  "9c6d210f6c61d0ec49fac4bf487a2d71966b1f3dd59653d8a8fdf12e04f9b306",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / tiny-focusgroup-helper

Package

Name
tiny-focusgroup-helper
View open source insights on deps.dev
Purl
pkg:npm/tiny-focusgroup-helper

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "thunderboltRegistry.js",
            "sha256":  "72cefe23c4ceb63af7f6e0031306415507928009c3859e3b5d7e6ce178987b02",
            "tlsh":  "376134a5b99df02166c33438cfbf404aa4bb85632d6caed0b44899f02f7985c01ba5f5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "tiny-focusgroup-helper-1.0.0.tgz",
            "hashes":  {
                "sha1":  "e39042d1d89dc3ff8f55c7c03414c3c695429059",
                "sha512_sri":  "sha512-O/ABISexj2nQkgLnUkKZoA0FaHRgqiFEsldOxbxJMO8dAuNtkv1ESwtM84HBZtLCYRWNqzz3Ywp/uBEO4ZSaQA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-focusgroup-helper/MAL-2026-17527.json"