some-very-long-package-name@3.0.0
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 3:53 PM UTC
OSV ID
MAL-2026-17778
Ecosystem
npm
Summary
Package ships a postinstall lifecycle hook (node beacon.cjs) and a top-level require('./beacon.cjs').fire() call in index.js, so both npm install and any require() of the package trigger an outbound HTTP POST to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The POST body is a JSON payload containing the installer's hostname (os.hostname()), the install path (__dirname), the current working directory (process.cwd()), and the Node.js version. The package exports no real functionality: index.js returns a Proxy whose property accesses all resolve to a no-op function, so the module's only effect is the beacon. The self-description as a 'Compatibility shim' combined with the generic package name and the no-op surface is consistent with a dependency-confusion / name-squat callback package targeting an internal package name.
Source: amazon-inspector (1ce120698c1be7e98866ccdff0987f7b77f53377e525284f311363b79f5ea397)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.