Logo
npm

xblaxw@99.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC

Malicious

OSV ID

MAL-2026-17708

Ecosystem

npm

Summary

xblaxw@1.1.0 is a stub package whose only behavior is a beacon. The package.json postinstall script runs node beacon.cjs, which collects host identifiers (hostname, install path, process.cwd(), process.version) and POSTs them as JSON to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plaintext HTTP. The same beacon is re-fired on require(): index.js exports a Proxy that returns a no-op function for any property access and calls require('./beacon.cjs').fire() on load, so the exfiltration also triggers whenever a consumer imports the package. The package description is 'Compatibility shim.' with no real functionality — the Proxy-of-noops export is consistent with a dependency-confusion / name-squat beacon designed to confirm which internal names resolve to this public package and report back installer host metadata to the operator at 185.158.107.175:8787.

Source: amazon-inspector (2d2e0b35582727d314517ea66b234f665258076783678cdf645075a7294a0aed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.