Vulnerability MAL-2026-1809

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 months ago
March 18, 2026 at 01:03 PM UTC
Malicious code in ph-common (npm)
0.1.0 - 3.0.0 and 77.7.7 and 99.0.1
0.1.0 - 3.0.0 and 77.7.7 and 99.0.1

Summary

Malicious code in ph-common (npm)

Details

ph-common is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise979 published these 8 versions on 2026-10-05 between 02:09 and 02:16 UTC.

Impacted packages

Timeline

Published
6 months ago
March 18, 2026 at 01:03 PM UTC
Last Modified
20 hours ago
October 05, 2026 at 04:15 AM UTC