-= Per source details. Do not edit below this line.=-
The package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency requests alongside a duplicate capitalized Dependencies key referencing request — the shape of a dependency-confusion probe rather than a functional library.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020207",
"import_time": "2026-09-21T03:24:21.352380542Z",
"modified_time": "2026-09-21T03:22:52Z",
"sha256": "dd57f799e0797ede7d18d6a36dd05c31c34d21b4e45d554730a8d08dd310cf73",
"source": "amazon-inspector",
"versions": [
"99.99.99"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "516803efbc40266c03927a1c42c8f96f6dd312f547b3b630f2de5f4bc15230da",
"tlsh": "a5c08cc2a382f39486f14986a529161a230df170b9fc44bae34c23ad488396d51a3ac1"
},
{
"path": "package.json",
"sha256": "8c3341690162c43530f6615a782d7ac7c45b176e791cf1bf1698fd06ff131a91",
"tlsh": "a9e09261cc509a7310fc13e968791b07b1626f2b42685c4f34f3b48d66a2126449ef29"
}
],
"package_integrity": [
{
"filename": "test1gg234-99.99.99.tgz",
"hashes": {
"sha1": "db6609bb78fc0dafdb00f26425eab73ca87fa543",
"sha512_sri": "sha512-C9MxN8EDSMrnwJTigOWAlXF8L0Fy0MJt+q/2//CgLEzD2soAopA9I2KGYk3Eu+VMilLAz+eCPQkutCOiQbcRQg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test1gg234/MAL-2026-16313.json"