{"id":"MAL-2026-17503","summary":"Malicious code in dom-focus-sentinel (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7baf5178b3cd02ae8e6e2c01e8cf305fd9670118428c4d3ef94ac0caef6fc4e8)\nthunderboltRegistry.js runs an immediately-invoked function at module load that uses child_process.execSync to run host reconnaissance commands (whoami, id, pwd, ifconfig, ip addr, cat /etc/hosts, hostname) and transmits each command's output, along with Node version, platform, and pid, via fetch GET requests to the hardcoded plain-HTTP endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. The package also structurally impersonates Wix internal registry modules by exporting factories keyed on thunderboltRegistry/siteAssetsRegistry/documentManagementRegistry/editorRegistry/corvidRegistry and shipping a manifest with static.parastorage.com unpkg URLs under dom-focus-sentinel@1.0.0, so the exfiltration IIFE fires whenever a consumer requires any of these registry names. The reconnaissance behavior is unrelated to the declared focus-sentinel purpose, and a `beacon=rce-poc` marker is embedded in the exfil traffic.\n","modified":"2026-10-04T23:45:19.912221146Z","published":"2026-10-04T23:28:40Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020975","import_time":"2026-10-04T23:40:47.576741398Z","modified_time":"2026-10-04T23:28:40Z","sha256":"7baf5178b3cd02ae8e6e2c01e8cf305fd9670118428c4d3ef94ac0caef6fc4e8","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dom-focus-sentinel/v/1.0.0"}],"affected":[{"package":{"name":"dom-focus-sentinel","ecosystem":"npm","purl":"pkg:npm/dom-focus-sentinel"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"c5823a5b4efa046453d6cc532602f7dd9efa1c7a35fc5585cfcab17bcef75cbd","tlsh":"4f7143a5b99df02196c37438cf7f904ea4bb86672c2caee4744859b01f3945c01ba5f4"}],"package_integrity":[{"filename":"dom-focus-sentinel-1.0.0.tgz","hashes":{"sha1":"0a924b42e3d9a3f7c7234ac65964a1eef026ebda","sha512_sri":"sha512-vnzYiikcSu2Fg4N7IibrKCjXbbPeyGjb6ddx4LW4bgXzgxBuSFrSedz60m1UKt3tX0dLah/SQsq28C9TnDprtQ=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dom-focus-sentinel/MAL-2026-17503.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}