nitro-cjs-requirer@99.0.1
Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC
OSV ID
MAL-2026-17775
Ecosystem
npm
Summary
The package is a beacon carrier with no real functionality. The declared postinstall script runs beacon.cjs, which POSTs the package name, os.hostname(), __dirname install path, process.cwd(), and node version to the hardcoded bare-IP, plain-HTTP endpoint http://185.158.107.175:8787/_ah/dc. The same fire() call is also invoked at module load from index.js, which otherwise exports a Proxy returning no-op functions for every property so the module appears to be a compatibility shim. Installer host identifiers are therefore sent unconditionally both at npm install (via the postinstall lifecycle hook) and on require(), to a bare-IP endpoint unrelated to any publisher, with no caller opt-in and no documented purpose. The shape — hollow stub module, dual install-time and require-time beacon trigger, hardcoded bare-IP over plain HTTP, host/path/cwd identifiers — is a dependency-confusion or build-pipeline reconnaissance probe.
Source: amazon-inspector (b78ca7e6d900dde3d7b9a367cdc359f3ec47a8b662ff53dd9c6542edbdb00b0b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.