Logo
npm

tiny-focusgroup-helper@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17527

Ecosystem

npm

Summary

tiny-focusgroup-helper@1.0.0 declares itself as a focus-group accessibility helper, but thunderboltRegistry.js runs an IIFE at require time that executes whoami, uname -a, ifconfig/ip addr, and reads /etc/hosts via child_process, and POSTs/GETs the output as query parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3, along with a beacon containing node version, platform, and pid. The dxpoc.gt.tc host is a dynamic-DNS domain unrelated to any legitimate publisher. The package's exported surface (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) mirrors internal Wix thunderbolt registry module names and the shipped manifest references static.parastorage.com, consistent with a dependency-confusion/module-impersonation lure targeting Wix build environments.

Source: amazon-inspector (9c6d210f6c61d0ec49fac4bf487a2d71966b1f3dd59653d8a8fdf12e04f9b306)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.