OSV ID
MAL-2026-17707
Ecosystem
npm
Summary
wie888r@3.0.0 ships a stub main (index.js) that exports a Proxy returning no-op functions for any property access, so bundlers that resolve this name do not crash. The package's postinstall script runs beacon.cjs, which collects host identifiers (hostname, install path, cwd, node version) and POSTs them to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. index.js invokes the same beacon on require, so the exfiltration fires both at install time and whenever the module is loaded. The destination is not a documented first-party service, and the package's self-described 'compatibility shim' purpose is contradicted by the beacon behavior. The combination of a no-op Proxy stub, a hardcoded non-publisher bare-IP endpoint, and dual install-time plus import-time reconnaissance is the standard shape of a dependency-confusion / typosquat probe used to confirm resolution of an unexpected name inside a target environment.
Source: amazon-inspector (b3f438329492b2e0f2917a0eebe97ad8149149b66cd5eb9201bed0b8f5750e7b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.