{"id":"MAL-2026-17491","summary":"Malicious code in focus-visible-polyfill-lite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5225b5a8636a589f9b90272ad04c3f4104670a23d5c24b45f6aeaa757a4f2a2b)\nThe package is advertised as a focus-visible polyfill but ships thunderboltRegistry.js, which impersonates Wix thunderbolt internal registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) via a Proxy-backed export stub. When the module is required, an IIFE at the top of the file uses child_process.execSync to run host reconnaissance commands (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) and sends the command output along with a beacon (Node version, platform, pid) via plain-HTTP GET requests to a hardcoded attacker-controlled endpoint at http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. The package self-labels the beacon as 'rce-poc'. The shape is a dependency-confusion / typosquat payload: a benign-sounding public package shadows Wix-internal registry names so that a build pipeline resolving these names from the public registry executes the reconnaissance payload with the installer's privileges on module load.\n","modified":"2026-10-04T23:30:06.639873273Z","published":"2026-10-04T23:12:40Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-04T23:16:29.879942944Z","modified_time":"2026-10-04T23:12:40Z","sha256":"5225b5a8636a589f9b90272ad04c3f4104670a23d5c24b45f6aeaa757a4f2a2b","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020876"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/focus-visible-polyfill-lite/v/1.0.0"}],"affected":[{"package":{"name":"focus-visible-polyfill-lite","ecosystem":"npm","purl":"pkg:npm/focus-visible-polyfill-lite"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"6717f66b7a71af1398876cee877318cb0f0107aa71e51e76c8e81a8f1d152925","tlsh":"107164a5f99df02065c33438cb7f404ab4bb85672d6caee0744899b02f7985c01be6f5","path":"thunderboltRegistry.js"}],"package_integrity":[{"filename":"focus-visible-polyfill-lite-1.0.0.tgz","hashes":{"sha1":"c444521a9daa2d9260427af4e52bfe159f669386","sha512_sri":"sha512-BcVlNNWYCVC26MzU2V/XYrwQtes87qu3u/O45LhlFjnHXtrwa2zO4lgej64awQigKth/Qd0Kr9b44yzYY+wLhg=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/focus-visible-polyfill-lite/MAL-2026-17491.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}