Logo
npm

nested-lib@1.1.0

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17773

Ecosystem

npm

Summary

The package declares scripts.postinstall = "node beacon.cjs" and index.js also invokes require('./beacon.cjs').fire() at module load. beacon.cjs POSTs a JSON payload containing os.hostname(), __dirname, process.cwd(), and process.version over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The destination is not a documented first-party service and the host identifiers are sent without any opt-in. index.js otherwise exports a Proxy that returns no-op functions for every property access, so the package provides no real functionality — its sole on-install and on-require effect is the beacon. The combination of a hollow Proxy shim, a bare-IP plain-HTTP destination, and automatic firing from both the npm lifecycle hook and the main module is consistent with a reconnaissance/confirmation beacon used to validate successful installation into target environments, typically preceding a second-stage payload.

Source: amazon-inspector (0a0b849de5330a4a4984a855f83ce1638b17e459d359312319ff35dc0e02f928)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.