ph-common@99.0.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-1809
Ecosystem
npm
Summary
The package is a stub whose index.js exports a Proxy returning no-op functions for every property access, so consumers that import it receive a non-functional module. The only functional code is beacon.cjs, which POSTs the installer's hostname, install path (__dirname), cwd, and Node version as JSON to the hardcoded bare-IP plain-HTTP endpoint http://185.158.107.175:8787/_ah/dc. The beacon fires both from the package.json postinstall lifecycle hook (node beacon.cjs) and at import time via a top-level require('./beacon.cjs').fire() in index.js. The destination is unrelated to any publisher infrastructure, uses a bare IP over cleartext HTTP, and the comments framing the payload as 'only machine/package metadata' do not change that unsolicited host identifiers are being sent off-host on install and on require. The stub-plus-beacon shape is consistent with a dependency-confusion or name-squat reconnaissance probe.
Source: amazon-inspector (f82053e651a1ec7ee7cdf8ecd57ca4be012f7ce8d60dec081f99c2b80cb66bf2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.