MAL-2026-17706

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testrrrd/MAL-2026-17706.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17706
Published
2026-10-08T21:22:08Z
Modified
2026-10-08T21:45:54Z
Summary
Malicious code in testrrrd (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad)

On npm install, package.json scripts.postinstall runs node beacon.cjs, which POSTs a JSON payload containing the installer's hostname (os.hostname()), install path (__dirname), current working directory (process.cwd()), Node version, and package identifier over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The same beacon is re-triggered at import time: index.js (the declared main) calls require('./beacon.cjs').fire() and then exports a Proxy whose get trap returns a no-op for any member access, so consumers importing arbitrary names from the package continue past the callback. The dual trigger ensures the callback fires even when lifecycle scripts are suppressed (e.g. npm install --ignore-scripts), and the Proxy shim conceals that the package provides no legitimate functionality. The destination is a bare IPv4 address on a non-standard port unrelated to any declared publisher, and the transport is unencrypted.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021260",
            "import_time": "2026-10-08T21:42:57.173961022Z",
            "modified_time": "2026-10-08T21:22:42Z",
            "sha256": "016351de268cd01a6a8f3cb2278b3735206e45c254b3b166c18bc0bf4abf17b6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021257",
            "import_time": "2026-10-08T21:42:56.965709286Z",
            "modified_time": "2026-10-08T21:22:15Z",
            "sha256": "84a7f8fd9d6de2f68ce889aa54d7492bbb2f7a4ac7c78542b27bb41cbb119a34",
            "source": "amazon-inspector",
            "versions": [
                "0.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021259",
            "import_time": "2026-10-08T21:42:57.095468254Z",
            "modified_time": "2026-10-08T21:22:32Z",
            "sha256": "91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad",
            "source": "amazon-inspector",
            "versions": [
                "3.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021267",
            "import_time": "2026-10-08T21:42:57.702053496Z",
            "modified_time": "2026-10-08T21:23:45Z",
            "sha256": "e94d33713dfab2a5d24334bd4dfc9f840fe8357174a540134724097d9da92156",
            "source": "amazon-inspector",
            "versions": [
                "99.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021258",
            "import_time": "2026-10-08T21:42:57.027994051Z",
            "modified_time": "2026-10-08T21:22:24Z",
            "sha256": "f3acddc2a24a30fe2bbb66b02f5da938bb888824a127915df5c86faec95ffe10",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021256",
            "import_time": "2026-10-08T21:42:56.84348094Z",
            "modified_time": "2026-10-08T21:22:08Z",
            "sha256": "0b2b8898408042377780b7012071a760128d4fcd83d0a3230cd1619036b427ed",
            "source": "amazon-inspector",
            "versions": [
                "1.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-021266",
            "import_time": "2026-10-08T21:42:57.621688314Z",
            "modified_time": "2026-10-08T21:23:37Z",
            "sha256": "767b0c5bd1f7cbd076d5564c333485255f96fe58c834757cf73d5d25c8d5c911",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / testrrrd

Package

Affected ranges

Affected versions

0.*
0.0.1
1.*
1.0.0
1.1.0
2.*
2.0.0
2.0.1
3.*
3.0.0
99.*
99.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.cjs",
            "sha256": "e2b8e936f7052e6459566e71c32ecd56ec6cfdf468a892ecc4ca0cf8081bc6c7",
            "tlsh": "d8316feba8e1a008aaab7098c54f0409b27af0068401ab50f95c82959f6193c33fa8dc"
        },
        {
            "path": "package.json",
            "sha256": "d04d3f709eae18877d31d2e7296e5741dd596cd4d84e981edce12ccd14749d51",
            "tlsh": "68d0a72089215e6364c56ee20e666e0a55a20d7f01147c083397505c46ed77729ff36d"
        }
    ],
    "package_integrity": [
        {
            "filename": "testrrrd-1.0.0.tgz",
            "hashes": {
                "sha1": "6a61d105b73e3f5ffef00ef4ca8d22856342170d",
                "sha512_sri": "sha512-G0aEuFlr3YlzNAsWANv887cXY9mfHTgrvaaOC28UIMDLSp1pOH5hhO+LZhzyCzmhHcFI1bEaiVnLLE1sRcbQUQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testrrrd/MAL-2026-17706.json"