Vulnerability MAL-2026-1809
Summary
Malicious code in ph-common (npm)
Details
ph-common is a dependency-confusion package: it is described as a "Compatibility shim", uses version numbers up to 99.0.1, and its README calls it an "authorized dependency-confusion test". Each listed version has a postinstall script that runs node beacon.cjs on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to http://185.158.107.175:8787/_ah/dc, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise979 published these 8 versions on 2026-10-05 between 02:09 and 02:16 UTC.