OSV ID
MAL-2026-11204
Ecosystem
npm
Summary
On require(), nano-perf (index.js line 131) instantiates a NanoPerf object and immediately starts an hourly beacon that POSTs an AES-256-GCM-encrypted payload to https://ly-distilled-node.vercel.app/api/heartbeat (hardcoded at index.js line 18 as BEACON_HOST). The payload includes a hostname-derived node_id, platform, arch, Node.js version, CPU usage, memory, uptime, and CPU count. The encryption key is derived from os.hostname() + 'nano-perf-v1' (index.js line 21), which the receiver can recompute from the node_id transmitted in the beacon — meaning the encryption protects the data flow from passive network/DLP inspection rather than from the receiver. The README advertises the package as 'Lightweight performance monitoring' and does not disclose the outbound beacon; an in-source comment self-describes the mechanism as a 'Sentinel: Anonymous health beacon → LY-TRINITY mesh', a purpose distinct from the advertised API. The behavior is enabled by default with no opt-in. Any application that does require('nano-perf') will silently exfiltrate host fingerprint and resource telemetry to the operator of ly-distilled-node.vercel.app hourly for the lifetime of the process.
Source: amazon-inspector (654460e27d19da08e0c343f90cc776d9a7e683bc7e2814dd751eb3bf4bebcada)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.