Logo
npm

another-very-long-name@2.0.1

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC

Malicious

OSV ID

MAL-2026-17767

Ecosystem

npm

Summary

another-very-long-name@1.0.1 ships a beacon.cjs that is invoked both from the declared postinstall lifecycle script and from the module's require()-time entry (index.js). On execution it collects host identifiers — hostname, install path, process.cwd(), process.version, OS metadata, and the package name — and POSTs them as JSON to the hardcoded cleartext endpoint http://185.158.107.175:8787/_ah/dc. The package exposes no genuine functionality: index.js returns a Proxy whose get handler returns a no-op for every property so that bundlers consuming the package do not fail, and an author comment states that a build that completes and calls back is cleaner evidence. The destination is a bare-IP HTTP endpoint with no first-party relationship to any declared publisher, and the stub-plus-beacon shape is consistent with a dependency-confusion reconnaissance probe rather than a compatibility shim.

Source: amazon-inspector (eea9e3cf3d973c07d09048435d4ddc496574ce222d650c228b1400d866ea3ccf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.