Skip to content

Malicious code in focus-visible-polyfill-lite (npm)

Malware Published Oct 5, 2026 to the GitHub Advisory Database • Updated Oct 5, 2026

Package

npm focus-visible-polyfill-lite (npm)

Affected versions

= 1.0.0

Patched versions

None

Description

Source: amazon-inspector (5225b5a8636a589f9b90272ad04c3f4104670a23d5c24b45f6aeaa757a4f2a2b)

The package is advertised as a focus-visible polyfill but ships thunderboltRegistry.js, which impersonates Wix thunderbolt internal registry modules (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) via a Proxy-backed export stub. When the module is required, an IIFE at the top of the file uses child_process.execSync to run host reconnaissance commands (id, whoami, uname -a, ifconfig/ip addr, cat /etc/hosts) and sends the command output along with a beacon (Node version, platform, pid) via plain-HTTP GET requests to a hardcoded attacker-controlled endpoint at http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. The package self-labels the beacon as 'rce-poc'. The shape is a dependency-confusion / typosquat payload: a benign-sounding public package shadows Wix-internal registry names so that a build pipeline resolving these names from the public registry executes the reconnaissance payload with the installer's privileges on module load.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Oct 5, 2026
Reviewed Oct 5, 2026
Last updated Oct 5, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-5h59-r5m3-rf9w

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.