Logo
npm

tiny-dom-focus-trap@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17526

Ecosystem

npm

Summary

The package is advertised as a focus-trap utility but thunderboltRegistry.js runs an IIFE at require time that uses child_process.execSync to run whoami, id, pwd, ifconfig / ip addr, hostname, and to read /etc/hosts, then sends each command's output as query parameters to http://dxpoc.gt.tc/callback.php via fetch. A separate beacon containing Node version, platform, and pid is also posted to the same endpoint. The package additionally impersonates Wix 'thunderbolt' internal registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry) and references static.parastorage.com manifest URLs, matching a dependency-confusion lure aimed at Wix build environments. Installing or importing this package causes the installer host's identity, network configuration, and /etc/hosts contents to be sent to an attacker-controlled host.

Source: amazon-inspector (84262096595a1e0ce09bbaa359930cd07cf420cc72545174ddc4f12c60bec962)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.