cloudflare_module@99.0.1
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 5:53 PM UTC
OSV ID
MAL-2026-17768
Ecosystem
npm
Summary
Package cloudflare_module@99.0.1 is a dependency-confusion lure targeting the cloudflare_* namespace. package.json declares scripts.postinstall: "node beacon.cjs", and beacon.cjs POSTs a JSON payload containing os.hostname(), the install path (__dirname), process.cwd(), and process.version to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. The package main (index.js) additionally calls require('./beacon.cjs').fire() at top level inside a try/catch, so the same host-identifier POST also fires whenever a downstream bundler or application require()s the package. The default export is a Proxy that returns a no-op for every property access, allowing bundlers that resolve an internal cloudflare_module name to complete the build cleanly so the beacon callback fires without producing errors. The package is published at version 99.0.1 with a generic "Compatibility shim." description, consistent with version-bumping to beat an internal registry during resolution. The README self-labels the package as an "authorized dependency-confusion test," but the beacon targets any machine that resolves the name — the installer never consents to the exfiltration — and the destination is an unattributed bare-IP collector, not infrastructure of the targeted namespace.
Source: amazon-inspector (f3a545e1e930894c3320e68c2aee17dd2cec7f20ed03b2e882905056d0eee242)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.