Vulnerability MAL-2026-17640

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 07, 2026 at 12:01 AM UTC
Malicious code in browser-metrics-plugin.contrib (npm)
0.0.1 - 99.0.1
0.0.1 - 99.0.1

Summary

Malicious code in browser-metrics-plugin.contrib (npm)

Details

browser-metrics-plugin.contrib is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise8887 published these 6 versions, and 7 versions of troubleshooting with the same payload, on 2026-10-07 between 00:01 and 00:07 UTC.

Timeline

Published
8 hours ago
October 07, 2026 at 12:01 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 06:45 AM UTC