Logo
npm

testrrrd@99.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC

Malicious

OSV ID

MAL-2026-17706

Ecosystem

npm

Summary

On npm install, package.json scripts.postinstall runs node beacon.cjs, which POSTs a JSON payload containing the installer's hostname (os.hostname()), install path (__dirname), current working directory (process.cwd()), Node version, and package identifier over plain HTTP to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The same beacon is re-triggered at import time: index.js (the declared main) calls require('./beacon.cjs').fire() and then exports a Proxy whose get trap returns a no-op for any member access, so consumers importing arbitrary names from the package continue past the callback. The dual trigger ensures the callback fires even when lifecycle scripts are suppressed (e.g. npm install --ignore-scripts), and the Proxy shim conceals that the package provides no legitimate functionality. The destination is a bare IPv4 address on a non-standard port unrelated to any declared publisher, and the transport is unencrypted.

Source: amazon-inspector (91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.