MAL-2026-17641

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/troubleshooting/MAL-2026-17641.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17641
Published
2026-10-07T00:04:15Z
Modified
2026-10-08T04:00:05Z
Summary
Malicious code in troubleshooting (npm)
Details

troubleshooting is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise8887 published these 7 versions, and 6 versions of browser-metrics-plugin.contrib with the same payload, on 2026-10-07 between 00:01 and 00:07 UTC.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (28103a0b6203c0917551439eb348f6b197e382fad4e84d9bf2cbaadd48012ccb)

troubleshooting@2.0.1 is a stub package whose only functional behavior is a reconnaissance beacon. package.json declares scripts.postinstall: node beacon.cjs, which runs on npm install, and index.js runs the same beacon on require('troubleshooting') before exporting a Proxy whose properties all return no-ops so consuming bundlers do not crash. beacon.cjs collects the package name, os.hostname(), __dirname (install path), process.cwd(), and process.version, and POSTs them as JSON to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. The README self-labels the package as an authorized dependency-confusion test, but the behavior is identical to a dependency-confusion exfiltration payload: any environment whose internal/private package name collides with troubleshooting on the public npm registry will have its build host, install path, working directory, and Node version reported to an outside party at a bare IP, providing actionable fingerprinting of internal build systems and CI runners.

Database specific
{
    "iocs": {
        "files": [
            {
                "digests": {
                    "sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d"
                },
                "note": "Main entry point; calls beacon.cjs fire() on import and exports a no-op Proxy. Identical in all listed versions.",
                "paths": [
                    "index.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "e5915aacc7fbf292ba1eaf2f2cd242e9370d82342016eed6787b81f3b0c2415b"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@0.1.0).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@0.1.0.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "8bb61cf793d6a8a2ade875d08993c30016a890bdbae69eed7f828aa1a7ae1888"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.0).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@1.0.0.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "06a7b88c50c12888cc1c9278e10c6be42cc79cc7fad022fed434c9b34aef1fef"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.1).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@1.0.1.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "fbfeb7d0471481120cce111bfcd150660861075b267fd0d4a121498cfd1fd79c"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@99.0.1).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@99.0.1.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9e36b9e2858eef92b637abc885aedc7cc3a745511d9da85391c45da8f91e142e"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@3.0.0).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@3.0.0.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "a6b1f6c20b2ce88e11c467a0df7c8570b8d25c549aadd04affb37310647fc4b4"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.1.0).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@1.1.0.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "28058651eb58dd8ce81d910e706ed48c15aeaf3b4a0c2ffe789ad329742f434f"
                },
                "note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@2.0.1).",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
                },
                "note": "Executed by the postinstall script of troubleshooting@2.0.1.",
                "paths": [
                    "beacon.cjs"
                ],
                "source": "PACKAGE_ARCHIVE"
            }
        ],
        "ips": [
            "185.158.107.175"
        ],
        "urls": [
            "http://185.158.107.175:8787/_ah/dc"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021120",
            "import_time": "2026-10-08T03:50:29.235704196Z",
            "modified_time": "2026-10-08T03:38:56Z",
            "sha256": "12b6f407e0af6cc239f1c478e20a35539c0fcfc55383b4c91bb28c8d761b6e0c",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021125",
            "import_time": "2026-10-08T03:50:29.516676825Z",
            "modified_time": "2026-10-08T03:39:42Z",
            "sha256": "1d90760032473b2d515d64b81a0a49c2c2721fe292e8202105b5c7ff2d9c62eb",
            "source": "amazon-inspector",
            "versions": [
                "3.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021123",
            "import_time": "2026-10-08T03:50:29.406955779Z",
            "modified_time": "2026-10-08T03:39:24Z",
            "sha256": "28103a0b6203c0917551439eb348f6b197e382fad4e84d9bf2cbaadd48012ccb",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021111",
            "import_time": "2026-10-08T03:50:28.586907761Z",
            "modified_time": "2026-10-08T03:37:38Z",
            "sha256": "2de8bb87c22c8d38bbe8802eda96645534386329c38faf8599659acd36f63f1f",
            "source": "amazon-inspector",
            "versions": [
                "1.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021127",
            "import_time": "2026-10-08T03:50:29.628697551Z",
            "modified_time": "2026-10-08T03:39:58Z",
            "sha256": "380314bcd4aa77f2a4ab4888c42977509fe75f3cd98dbaebfabee9c5802f94a3",
            "source": "amazon-inspector",
            "versions": [
                "0.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021122",
            "import_time": "2026-10-08T03:50:29.342816973Z",
            "modified_time": "2026-10-08T03:39:15Z",
            "sha256": "3f72779e9bac9b888cd1ce0469e24b47bb787ab79a82ae0a48a7197921699469",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021102",
            "import_time": "2026-10-08T03:50:28.00849661Z",
            "modified_time": "2026-10-08T03:36:11Z",
            "sha256": "528ab481d195c2bbda3a82684d945456dab74b48db46f90b5f65cb98b6d5a2ee",
            "source": "amazon-inspector",
            "versions": [
                "99.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / troubleshooting

Package

Name
troubleshooting
View open source insights on deps.dev
Purl
pkg:npm/troubleshooting

Affected ranges

Affected versions

0.*
0.1.0
1.*
1.0.0
1.0.1
1.1.0
2.*
2.0.1
3.*
3.0.0
99.*
99.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.cjs",
            "sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531",
            "tlsh": "363141eba8e1e0489aaa7098c54f1409f17bf4069501af54fd5c82955f6153c33fa8dc"
        },
        {
            "path": "index.js",
            "sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d",
            "tlsh": "2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"
        }
    ],
    "package_integrity": [
        {
            "filename": "troubleshooting-1.0.1.tgz",
            "hashes": {
                "sha1": "2d771f0fdac3bda213237ca3ecd4925885e016e4",
                "sha512_sri": "sha512-B8uhPtSmrwNhV6Tvx0G4SpqwXnvq8G0dnje4l170FYNsBJUVUYljg4/b9N2hAbJWIjp59/cS5lMm8tK+quHR+Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/troubleshooting/MAL-2026-17641.json"