-= Per source details. Do not edit below this line.=-
The package ships a postinstall script (scripts.postinstall runs node beacon.cjs) and a top-level require('./beacon.cjs').fire() in index.js that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The exfiltration fires automatically both on npm install and on any require() of the package. index.js otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021268",
"import_time": "2026-10-08T21:42:57.762614731Z",
"modified_time": "2026-10-08T21:23:51Z",
"sha256": "093f62f129fa3bb6fb05829e930449393d54a9d5e72a5188aaa542a26b0ce368",
"source": "amazon-inspector",
"versions": [
"2.0.1"
]
},
{
"id": "IN-MAL-2026-021252",
"import_time": "2026-10-08T21:42:56.519207066Z",
"modified_time": "2026-10-08T21:21:34Z",
"sha256": "4a04b2b4f02f5d06a3729f210aa1ec9844c54ad8b1653677fc6e3d62e7f18549",
"source": "amazon-inspector",
"versions": [
"2.0.0"
]
},
{
"id": "IN-MAL-2026-021253",
"import_time": "2026-10-08T21:42:56.623622268Z",
"modified_time": "2026-10-08T21:21:42Z",
"sha256": "73ce932992891761028144293d7b2e414208fee2695adccf3d09bbd8751f3f79",
"source": "amazon-inspector",
"versions": [
"0.0.1"
]
},
{
"id": "IN-MAL-2026-021255",
"import_time": "2026-10-08T21:42:56.780389011Z",
"modified_time": "2026-10-08T21:22:00Z",
"sha256": "e194808ec33e50a585181e38b0359bd1f04e848fd87aa06c6bca80bbde2a50a7",
"source": "amazon-inspector",
"versions": [
"3.0.0"
]
},
{
"id": "IN-MAL-2026-021251",
"import_time": "2026-10-08T21:42:56.457783297Z",
"modified_time": "2026-10-08T21:21:26Z",
"sha256": "e7fce4d8536bf6254aa0791b2d048874ea7cc153303b68e28aa7e296493b342e",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-021269",
"import_time": "2026-10-08T21:42:57.845095126Z",
"modified_time": "2026-10-08T21:23:58Z",
"sha256": "0e87a3919d1aeb1d6b9f3069d72f5098fe92fbafc821448753dc650745ff0f62",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-021250",
"import_time": "2026-10-08T21:42:56.358827821Z",
"modified_time": "2026-10-08T21:21:17Z",
"sha256": "2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.cjs",
"sha256": "b90b0687de31609c4a0ed88db0d1979d33b510ec8e772abc2102b169766f09e7",
"tlsh": "3f3161eba8f1a0489aa77098c54f0409f17bf0068401ab50f95c82955f6153c33fa8dc"
},
{
"path": "index.js",
"sha256": "a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d",
"tlsh": "2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"
}
],
"package_integrity": [
{
"filename": "testrrrdd-2.0.1.tgz",
"hashes": {
"sha1": "f15a8241a11d830a39d4a0aa33a42d8a61d5a80c",
"sha512_sri": "sha512-oZCcmW2AH5v1a7iMachtLDnfIVWvO2xnVOibjbAuMDtV4BSo+jr3XyQW8moa1MyMWrxL8NWa3yJHB2J3RuUatA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wxwxtest/testrrrdd/MAL-2026-17704.json"