Vulnerability MAL-2026-17641

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 07, 2026 at 12:04 AM UTC
Malicious code in troubleshooting (npm)
0.1.0 - 99.0.1
0.1.0 - 99.0.1

Summary

Malicious code in troubleshooting (npm)

Details

troubleshooting is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise8887 published these 7 versions, and 6 versions of browser-metrics-plugin.contrib with the same payload, on 2026-10-07 between 00:01 and 00:07 UTC.

Impacted packages

Timeline

Published
8 hours ago
October 07, 2026 at 12:04 AM UTC
Last Modified
1 hour ago
October 07, 2026 at 06:45 AM UTC