@kibt/www-nuxt-i18n@99.0.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17498
Ecosystem
npm
Summary
The package is a stub whose index.js exports a Proxy returning no-op functions for every property access, allowing bundlers that import any member of the expected real package to succeed. The package.json declares a postinstall script node beacon.cjs, and index.js also loads the same beacon at require() time. beacon.cjs collects installer host metadata — os.hostname(), the install directory (__dirname), process.cwd(), and process.version — and POSTs it to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The destination is not affiliated with any legitimate publisher, the package provides no real functionality, and an in-source comment frames successful installs as evidence of a hit — matching the canonical dependency-confusion / namesquat validator shape where host identity is reported back to the operator to confirm which internal environments resolved the attacker-controlled scoped name.
Source: amazon-inspector (5ab1895c73507311b9efd31e40015529d9d7735c87e50cf3b714e6e520205ec4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.