troubleshooting is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise8887 published these 7 versions, and 6 versions of browser-metrics-plugin.contrib with the same payload, on 2026-10-07 between 00:01 and 00:07 UTC.
-= Per source details. Do not edit below this line.=-
troubleshooting@2.0.1 is a stub package whose only functional behavior is a reconnaissance beacon. package.json declares scripts.postinstall: node beacon.cjs, which runs on npm install, and index.js runs the same beacon on require('troubleshooting') before exporting a Proxy whose properties all return no-ops so consuming bundlers do not crash. beacon.cjs collects the package name, os.hostname(), __dirname (install path), process.cwd(), and process.version, and POSTs them as JSON to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. The README self-labels the package as an authorized dependency-confusion test, but the behavior is identical to a dependency-confusion exfiltration payload: any environment whose internal/private package name collides with troubleshooting on the public npm registry will have its build host, install path, working directory, and Node version reported to an outside party at a bare IP, providing actionable fingerprinting of internal build systems and CI runners.
{
"iocs": {
"files": [
{
"digests": {
"sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d"
},
"note": "Main entry point; calls beacon.cjs fire() on import and exports a no-op Proxy. Identical in all listed versions.",
"paths": [
"index.js"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "e5915aacc7fbf292ba1eaf2f2cd242e9370d82342016eed6787b81f3b0c2415b"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@0.1.0).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@0.1.0.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "8bb61cf793d6a8a2ade875d08993c30016a890bdbae69eed7f828aa1a7ae1888"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.0).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@1.0.0.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "06a7b88c50c12888cc1c9278e10c6be42cc79cc7fad022fed434c9b34aef1fef"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.1).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@1.0.1.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "fbfeb7d0471481120cce111bfcd150660861075b267fd0d4a121498cfd1fd79c"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@99.0.1).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@99.0.1.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9e36b9e2858eef92b637abc885aedc7cc3a745511d9da85391c45da8f91e142e"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@3.0.0).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@3.0.0.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "a6b1f6c20b2ce88e11c467a0df7c8570b8d25c549aadd04affb37310647fc4b4"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.1.0).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@1.1.0.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "28058651eb58dd8ce81d910e706ed48c15aeaf3b4a0c2ffe789ad329742f434f"
},
"note": "postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@2.0.1).",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"
},
"note": "Executed by the postinstall script of troubleshooting@2.0.1.",
"paths": [
"beacon.cjs"
],
"source": "PACKAGE_ARCHIVE"
}
],
"ips": [
"185.158.107.175"
],
"urls": [
"http://185.158.107.175:8787/_ah/dc"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021120",
"import_time": "2026-10-08T03:50:29.235704196Z",
"modified_time": "2026-10-08T03:38:56Z",
"sha256": "12b6f407e0af6cc239f1c478e20a35539c0fcfc55383b4c91bb28c8d761b6e0c",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-021125",
"import_time": "2026-10-08T03:50:29.516676825Z",
"modified_time": "2026-10-08T03:39:42Z",
"sha256": "1d90760032473b2d515d64b81a0a49c2c2721fe292e8202105b5c7ff2d9c62eb",
"source": "amazon-inspector",
"versions": [
"3.0.0"
]
},
{
"id": "IN-MAL-2026-021123",
"import_time": "2026-10-08T03:50:29.406955779Z",
"modified_time": "2026-10-08T03:39:24Z",
"sha256": "28103a0b6203c0917551439eb348f6b197e382fad4e84d9bf2cbaadd48012ccb",
"source": "amazon-inspector",
"versions": [
"2.0.1"
]
},
{
"id": "IN-MAL-2026-021111",
"import_time": "2026-10-08T03:50:28.586907761Z",
"modified_time": "2026-10-08T03:37:38Z",
"sha256": "2de8bb87c22c8d38bbe8802eda96645534386329c38faf8599659acd36f63f1f",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
},
{
"id": "IN-MAL-2026-021127",
"import_time": "2026-10-08T03:50:29.628697551Z",
"modified_time": "2026-10-08T03:39:58Z",
"sha256": "380314bcd4aa77f2a4ab4888c42977509fe75f3cd98dbaebfabee9c5802f94a3",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-021122",
"import_time": "2026-10-08T03:50:29.342816973Z",
"modified_time": "2026-10-08T03:39:15Z",
"sha256": "3f72779e9bac9b888cd1ce0469e24b47bb787ab79a82ae0a48a7197921699469",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-021102",
"import_time": "2026-10-08T03:50:28.00849661Z",
"modified_time": "2026-10-08T03:36:11Z",
"sha256": "528ab481d195c2bbda3a82684d945456dab74b48db46f90b5f65cb98b6d5a2ee",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.cjs",
"sha256": "9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531",
"tlsh": "363141eba8e1e0489aaa7098c54f1409f17bf4069501af54fd5c82955f6153c33fa8dc"
},
{
"path": "index.js",
"sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d",
"tlsh": "2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"
}
],
"package_integrity": [
{
"filename": "troubleshooting-1.0.1.tgz",
"hashes": {
"sha1": "2d771f0fdac3bda213237ca3ecd4925885e016e4",
"sha512_sri": "sha512-B8uhPtSmrwNhV6Tvx0G4SpqwXnvq8G0dnje4l170FYNsBJUVUYljg4/b9N2hAbJWIjp59/cS5lMm8tK+quHR+Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/troubleshooting/MAL-2026-17641.json"