Logo
npm

test1gg234@99.99.99

Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 7:43 AM UTC

Malicious

OSV ID

MAL-2026-16313

Ecosystem

npm

Summary

The package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency requests alongside a duplicate capitalized Dependencies key referencing request — the shape of a dependency-confusion probe rather than a functional library.

Source: amazon-inspector (dd57f799e0797ede7d18d6a36dd05c31c34d21b4e45d554730a8d08dd310cf73)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.