MAL-2026-17704

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wxwxtest/testrrrdd/MAL-2026-17704.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17704
Published
2026-10-08T21:21:17Z
Modified
2026-10-08T21:45:48Z
Summary
Malicious code in @wxwxtest/testrrrdd (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34)

The package ships a postinstall script (scripts.postinstall runs node beacon.cjs) and a top-level require('./beacon.cjs').fire() in index.js that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The exfiltration fires automatically both on npm install and on any require() of the package. index.js otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021268",
            "import_time": "2026-10-08T21:42:57.762614731Z",
            "modified_time": "2026-10-08T21:23:51Z",
            "sha256": "093f62f129fa3bb6fb05829e930449393d54a9d5e72a5188aaa542a26b0ce368",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021252",
            "import_time": "2026-10-08T21:42:56.519207066Z",
            "modified_time": "2026-10-08T21:21:34Z",
            "sha256": "4a04b2b4f02f5d06a3729f210aa1ec9844c54ad8b1653677fc6e3d62e7f18549",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021253",
            "import_time": "2026-10-08T21:42:56.623622268Z",
            "modified_time": "2026-10-08T21:21:42Z",
            "sha256": "73ce932992891761028144293d7b2e414208fee2695adccf3d09bbd8751f3f79",
            "source": "amazon-inspector",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021255",
            "import_time": "2026-10-08T21:42:56.780389011Z",
            "modified_time": "2026-10-08T21:22:00Z",
            "sha256": "e194808ec33e50a585181e38b0359bd1f04e848fd87aa06c6bca80bbde2a50a7",
            "source": "amazon-inspector",
            "versions": [
                "3.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021251",
            "import_time": "2026-10-08T21:42:56.457783297Z",
            "modified_time": "2026-10-08T21:21:26Z",
            "sha256": "e7fce4d8536bf6254aa0791b2d048874ea7cc153303b68e28aa7e296493b342e",
            "source": "amazon-inspector",
            "versions": [
                "0.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021269",
            "import_time": "2026-10-08T21:42:57.845095126Z",
            "modified_time": "2026-10-08T21:23:58Z",
            "sha256": "0e87a3919d1aeb1d6b9f3069d72f5098fe92fbafc821448753dc650745ff0f62",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021250",
            "import_time": "2026-10-08T21:42:56.358827821Z",
            "modified_time": "2026-10-08T21:21:17Z",
            "sha256": "2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @wxwxtest/testrrrdd

Package

Name
@wxwxtest/testrrrdd
View open source insights on deps.dev
Purl
pkg:npm/%40wxwxtest/testrrrdd

Affected ranges

Affected versions

0.*
0.0.1
0.1.0
1.*
1.0.0
1.0.1
2.*
2.0.0
2.0.1
3.*
3.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.cjs",
            "sha256": "b90b0687de31609c4a0ed88db0d1979d33b510ec8e772abc2102b169766f09e7",
            "tlsh": "3f3161eba8f1a0489aa77098c54f0409f17bf0068401ab50f95c82955f6153c33fa8dc"
        },
        {
            "path": "index.js",
            "sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d",
            "tlsh": "2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"
        }
    ],
    "package_integrity": [
        {
            "filename": "testrrrdd-2.0.1.tgz",
            "hashes": {
                "sha1": "f15a8241a11d830a39d4a0aa33a42d8a61d5a80c",
                "sha512_sri": "sha512-oZCcmW2AH5v1a7iMachtLDnfIVWvO2xnVOibjbAuMDtV4BSo+jr3XyQW8moa1MyMWrxL8NWa3yJHB2J3RuUatA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wxwxtest/testrrrdd/MAL-2026-17704.json"