testrrrd@99.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC
OSV ID
MAL-2026-17706
Ecosystem
npm
Summary
On npm install, package.json scripts.postinstall runs node beacon.cjs, which POSTs a JSON payload containing the installer's hostname (os.hostname()), install path (__dirname), current working directory (process.cwd()), Node version, and package identifier over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The same beacon is re-triggered at import time: index.js (the declared main) calls require('./beacon.cjs').fire() and then exports a Proxy whose get trap returns a no-op for any member access, so consumers importing arbitrary names from the package continue past the callback. The dual trigger ensures the callback fires even when lifecycle scripts are suppressed (e.g. npm install --ignore-scripts), and the Proxy shim conceals that the package provides no legitimate functionality. The destination is a bare IPv4 address on a non-standard port unrelated to any declared publisher, and the transport is unencrypted.
Source: amazon-inspector (91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.