Logo
npm

nitro-cjs-requirer@99.0.1

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC

Malicious

OSV ID

MAL-2026-17775

Ecosystem

npm

Summary

The package is a beacon carrier with no real functionality. The declared postinstall script runs beacon.cjs, which POSTs the package name, os.hostname(), __dirname install path, process.cwd(), and node version to the hardcoded bare-IP, plain-HTTP endpoint http://185.158.107.175:8787/_ah/dc. The same fire() call is also invoked at module load from index.js, which otherwise exports a Proxy returning no-op functions for every property so the module appears to be a compatibility shim. Installer host identifiers are therefore sent unconditionally both at npm install (via the postinstall lifecycle hook) and on require(), to a bare-IP endpoint unrelated to any publisher, with no caller opt-in and no documented purpose. The shape — hollow stub module, dual install-time and require-time beacon trigger, hardcoded bare-IP over plain HTTP, host/path/cwd identifiers — is a dependency-confusion or build-pipeline reconnaissance probe.

Source: amazon-inspector (b78ca7e6d900dde3d7b9a367cdc359f3ec47a8b662ff53dd9c6542edbdb00b0b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.