-= Per source details. Do not edit below this line.=-
On npm install, package.json scripts.postinstall runs node beacon.cjs, which POSTs a JSON payload containing the installer's hostname (os.hostname()), install path (__dirname), current working directory (process.cwd()), Node version, and package identifier over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The same beacon is re-triggered at import time: index.js (the declared main) calls require('./beacon.cjs').fire() and then exports a Proxy whose get trap returns a no-op for any member access, so consumers importing arbitrary names from the package continue past the callback. The dual trigger ensures the callback fires even when lifecycle scripts are suppressed (e.g. npm install --ignore-scripts), and the Proxy shim conceals that the package provides no legitimate functionality. The destination is a bare IPv4 address on a non-standard port unrelated to any declared publisher, and the transport is unencrypted.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021260",
"import_time": "2026-10-08T21:42:57.173961022Z",
"modified_time": "2026-10-08T21:22:42Z",
"sha256": "016351de268cd01a6a8f3cb2278b3735206e45c254b3b166c18bc0bf4abf17b6",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-021257",
"import_time": "2026-10-08T21:42:56.965709286Z",
"modified_time": "2026-10-08T21:22:15Z",
"sha256": "84a7f8fd9d6de2f68ce889aa54d7492bbb2f7a4ac7c78542b27bb41cbb119a34",
"source": "amazon-inspector",
"versions": [
"0.0.1"
]
},
{
"id": "IN-MAL-2026-021259",
"import_time": "2026-10-08T21:42:57.095468254Z",
"modified_time": "2026-10-08T21:22:32Z",
"sha256": "91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad",
"source": "amazon-inspector",
"versions": [
"3.0.0"
]
},
{
"id": "IN-MAL-2026-021267",
"import_time": "2026-10-08T21:42:57.702053496Z",
"modified_time": "2026-10-08T21:23:45Z",
"sha256": "e94d33713dfab2a5d24334bd4dfc9f840fe8357174a540134724097d9da92156",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
},
{
"id": "IN-MAL-2026-021258",
"import_time": "2026-10-08T21:42:57.027994051Z",
"modified_time": "2026-10-08T21:22:24Z",
"sha256": "f3acddc2a24a30fe2bbb66b02f5da938bb888824a127915df5c86faec95ffe10",
"source": "amazon-inspector",
"versions": [
"2.0.1"
]
},
{
"id": "IN-MAL-2026-021256",
"import_time": "2026-10-08T21:42:56.84348094Z",
"modified_time": "2026-10-08T21:22:08Z",
"sha256": "0b2b8898408042377780b7012071a760128d4fcd83d0a3230cd1619036b427ed",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
},
{
"id": "IN-MAL-2026-021266",
"import_time": "2026-10-08T21:42:57.621688314Z",
"modified_time": "2026-10-08T21:23:37Z",
"sha256": "767b0c5bd1f7cbd076d5564c333485255f96fe58c834757cf73d5d25c8d5c911",
"source": "amazon-inspector",
"versions": [
"2.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.cjs",
"sha256": "e2b8e936f7052e6459566e71c32ecd56ec6cfdf468a892ecc4ca0cf8081bc6c7",
"tlsh": "d8316feba8e1a008aaab7098c54f0409b27af0068401ab50f95c82959f6193c33fa8dc"
},
{
"path": "package.json",
"sha256": "d04d3f709eae18877d31d2e7296e5741dd596cd4d84e981edce12ccd14749d51",
"tlsh": "68d0a72089215e6364c56ee20e666e0a55a20d7f01147c083397505c46ed77729ff36d"
}
],
"package_integrity": [
{
"filename": "testrrrd-1.0.0.tgz",
"hashes": {
"sha1": "6a61d105b73e3f5ffef00ef4ca8d22856342170d",
"sha512_sri": "sha512-G0aEuFlr3YlzNAsWANv887cXY9mfHTgrvaaOC28UIMDLSp1pOH5hhO+LZhzyCzmhHcFI1bEaiVnLLE1sRcbQUQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testrrrd/MAL-2026-17706.json"