@wxwxtest/testrrrdd@3.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC
OSV ID
MAL-2026-17704
Ecosystem
npm
Summary
The package ships a postinstall script (scripts.postinstall runs node beacon.cjs) and a top-level require('./beacon.cjs').fire() in index.js that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The exfiltration fires automatically both on npm install and on any require() of the package. index.js otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon.
Source: amazon-inspector (2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.