a11y-tabindex-manager@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17501
Ecosystem
npm
Summary
a11y-tabindex-manager ships thunderboltRegistry.js, which executes an IIFE on module load that runs a series of local shell commands (cat /etc/hosts, whoami, id, pwd, ifconfig/ip addr, hostname, cat /etc/resolv.conf, uname -a, env | head -50) via child_process.execSync and POSTs each output over plain HTTP to the hardcoded endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. A separate beacon labeled 'rce-poc-v3' sends Node.js version, platform, and PID to the same host. child_process is acquired both directly and via a fallback that instantiates a new Module (new module.constructor()) and copies module.paths — an evasion technique to bypass simple require('child_process') scans. The package name resembles a generic accessibility helper, but the shipped registry entry performs host identity, network configuration, user, and environment-variable harvesting with no legitimate purpose.
Source: amazon-inspector (ce127c3e1cadd4f544a5f2580f2db030e3d9e3667d7b0e3399d85b59eb354045)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.