-= Per source details. Do not edit below this line.=-
Package declares both preinstall and postinstall lifecycle hooks that execute index.js on npm install. index.js issues an HTTP GET to the hardcoded bare IP 128.199.122.145 over plain HTTP, embedding the package name in the query string (http://128.199.122.145/?test1hh235). Manifest shape is consistent with a dependency-confusion reconnaissance probe: version 99.99.99 (implausibly high to win resolution against an internal package), empty description, and a typo-prone name. The beacon fires automatically during install and signals successful resolution/installation to an attacker-controlled host, confirming the target environment for follow-on attack.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020208",
"import_time": "2026-09-21T03:24:21.631054197Z",
"modified_time": "2026-09-21T03:23:01Z",
"sha256": "c9c95dc5aea7805ca50e114bae45747a46edb7331311044b0d3730e303d4351a",
"source": "amazon-inspector",
"versions": [
"99.99.99"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "129935ea1b3fdc6a7e4520d292016a7392be70150e25a08f27734bec451f0544",
"tlsh": "89c08cc26382f38486f9088369291616230df170b9fc04b6e34c63ae489396d11a3ac1"
},
{
"path": "package.json",
"sha256": "5eae61ba4b622d5d28e9571d0d08a0fe8ff85512b89778c353627c8557faa761",
"tlsh": "bde09261cc509a7310fc12e568791b07f1625f2b82685c0b34f3b48d66a2126449ef29"
}
],
"package_integrity": [
{
"filename": "test1hh235-99.99.99.tgz",
"hashes": {
"sha1": "612eafede0c18009855b78e5a57881c81403a2fb",
"sha512_sri": "sha512-3jS2BoDc41uOGgEagxN4fIzWW/YhmbdgMpawrmMmmnnL/9/4LmfJB8Bg685iAKQiROZ603OGaFMrH5eiLeRW9w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test1hh235/MAL-2026-16314.json"