Logo
npm

nitro-bundled-dep@99.0.1

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17774

Ecosystem

npm

Summary

nitro-bundled-dep@99.0.1 ships a stub main module (a Proxy that no-ops any property access) plus beacon.cjs, which runs both from the postinstall lifecycle hook (node beacon.cjs) and on top-level require() of index.js. The beacon reads os.hostname(), __dirname (install path), process.cwd(), and process.version and POSTs them over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The destination is not caller-configurable, is not associated with any published vendor, and has no relationship to the stated package purpose. The package name combined with version 99.0.1 and the inert stub body matches a dependency-confusion shape: an internal name resolved against the public registry at an implausibly high version pulls this beacon into the install, giving the operator of 185.158.107.175 confirmation of the host plus reconnaissance identifiers.

Source: amazon-inspector (0bbd4417bf91aba92399be259604511102ec5dfbacebe278a7922cf10c4deac5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.