Logo
npm

some-very-long-package-name@99.0.1

Vulnerability report · Last retrieved from osv.dev October 11, 2026 at 6:53 PM UTC

Malicious

OSV ID

MAL-2026-17778

Ecosystem

npm

Summary

The package is a stub whose main module exports a Proxy that returns a no-op for every property access, providing none of the functionality implied by the package name or its 'compatibility shim' description. Its only real behavior is beacon.cjs, which collects host and install identifiers (hostname, install path, process.cwd(), process.version, package name/user-agent) and POSTs them to the hardcoded bare-IP HTTP endpoint http://185.158.107.175:8787/_ah/dc. The beacon fires both automatically at install time via scripts.postinstall and again when the module is loaded via require(), because index.js invokes beacon.fire(). The shape — stub module, hardcoded non-DNS bare-IP C2 over plain HTTP, collection of installer host identifiers at install and require time — is consistent with a dependency-confusion / internal-name-squat reconnaissance beacon reporting successful installation inside private build environments.

Source: amazon-inspector (58c08ea2abb307f6ecb9a1896fcc3980e9a1eaf8b29044db67cd985654e1db16)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.