cloudflare_module@3.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17768
Ecosystem
npm
Summary
cloudflare_module@1.0.1 is a typosquat of Cloudflare branding whose only functional code is an install- and import-time beacon. beacon.cjs defines BEACON = "http://185.158.107.175:8787/_ah/dc" and a fire() function that POSTs a JSON payload containing os.hostname(), __dirname (installPath), process.cwd(), process.version and the package name to that hardcoded bare-IP HTTP endpoint. fire() is invoked from the package's postinstall script, so it runs automatically on npm install, and from the main module, so it also runs on require('cloudflare_module'). The package's main entry exports a Proxy of no-op functions (module.exports = new Proxy({}, { get:... return _noop; })) with a generic "Compatibility shim" description, so the package provides no legitimate functionality — the exfil beacon is its sole behavior. The destination is a bare IPv4 address on a non-standard port over cleartext HTTP, with no relationship to Cloudflare or any documented publisher. Host identity, install path and working directory shipped to an attacker-controlled collector constitute reconnaissance of installer environments suitable for targeted follow-on supply-chain exploitation.
Source: amazon-inspector (14316e66f8d8eeb53b5fd4850537ac5398947feaf88f3837e39bfa587f60a0fb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.