browser-metrics-plugin.contrib@99.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC
OSV ID
MAL-2026-17640
Ecosystem
npm
Summary
browser-metrics-plugin.contrib@1.0.1 ships beacon.cjs which POSTs a JSON payload containing os.hostname(), __dirname (install path), process.cwd(), and Node version to the hardcoded cleartext bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The beacon fires twice: once from a postinstall lifecycle hook on npm install, and again at require time from index.js (the declared main), which calls require('./beacon.cjs').fire() at top level inside a try/catch. The module exports a Proxy of no-ops so that load failures do not break the surrounding build, concealing the beacon's presence. The second trigger ensures the callback fires even when scripts are disabled via --ignore-scripts. The combination of hardcoded bare-IP destination (no TLS, no domain), host identifier collection at install and import time, dual-trigger design, and silencing wrapper is the canonical dependency-confusion exfiltration shape. A README self-label as a 'research' or 'dependency-confusion test' package is author-controlled and does not constitute installer consent; the hostname and install path disclose internal corporate build infrastructure to a third party.
Source: amazon-inspector (b1483de01fa77ef2e754624666b2c65ee4d2aff5ab261e38e3eb3f111b7efded)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.