{"id":"MAL-2026-17641","summary":"Malicious code in troubleshooting (npm)","details":"troubleshooting is a dependency-confusion package: it is described as a \"Compatibility shim\", uses version numbers up to 99.0.1, and its README calls it an \"authorized dependency-confusion test\". Each listed version has a postinstall script that runs `node beacon.cjs` on npm install, and index.js calls the same code when the package is imported; it POSTs the hostname, install path and current working directory over plain HTTP to `http://185.158.107.175:8787/_ah/dc`, and index.js exports a Proxy that returns no-op functions so builds importing the real package keep running. The npm account xwise8887 published these 7 versions, and 6 versions of browser-metrics-plugin.contrib with the same payload, on 2026-10-07 between 00:01 and 00:07 UTC.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (28103a0b6203c0917551439eb348f6b197e382fad4e84d9bf2cbaadd48012ccb)\ntroubleshooting@2.0.1 is a stub package whose only functional behavior is a reconnaissance beacon. package.json declares `scripts.postinstall: node beacon.cjs`, which runs on `npm install`, and index.js runs the same beacon on `require('troubleshooting')` before exporting a Proxy whose properties all return no-ops so consuming bundlers do not crash. beacon.cjs collects the package name, `os.hostname()`, `__dirname` (install path), `process.cwd()`, and `process.version`, and POSTs them as JSON to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plain HTTP. The README self-labels the package as an authorized dependency-confusion test, but the behavior is identical to a dependency-confusion exfiltration payload: any environment whose internal/private package name collides with `troubleshooting` on the public npm registry will have its build host, install path, working directory, and Node version reported to an outside party at a bare IP, providing actionable fingerprinting of internal build systems and CI runners.\n","modified":"2026-10-08T04:00:05.452128513Z","published":"2026-10-07T00:04:15Z","database_specific":{"iocs":{"ips":["185.158.107.175"],"urls":["http://185.158.107.175:8787/_ah/dc"],"files":[{"paths":["index.js"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d"},"note":"Main entry point; calls beacon.cjs fire() on import and exports a no-op Proxy. Identical in all listed versions."},{"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@0.1.0).","paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"e5915aacc7fbf292ba1eaf2f2cd242e9370d82342016eed6787b81f3b0c2415b"}},{"note":"Executed by the postinstall script of troubleshooting@0.1.0.","paths":["beacon.cjs"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"}},{"digests":{"sha256":"8bb61cf793d6a8a2ade875d08993c30016a890bdbae69eed7f828aa1a7ae1888"},"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.0).","paths":["package.json"],"source":"PACKAGE_ARCHIVE"},{"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"},"note":"Executed by the postinstall script of troubleshooting@1.0.0.","paths":["beacon.cjs"]},{"digests":{"sha256":"06a7b88c50c12888cc1c9278e10c6be42cc79cc7fad022fed434c9b34aef1fef"},"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.0.1).","paths":["package.json"],"source":"PACKAGE_ARCHIVE"},{"digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"},"note":"Executed by the postinstall script of troubleshooting@1.0.1.","paths":["beacon.cjs"],"source":"PACKAGE_ARCHIVE"},{"digests":{"sha256":"fbfeb7d0471481120cce111bfcd150660861075b267fd0d4a121498cfd1fd79c"},"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@99.0.1).","paths":["package.json"],"source":"PACKAGE_ARCHIVE"},{"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"},"note":"Executed by the postinstall script of troubleshooting@99.0.1.","paths":["beacon.cjs"]},{"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@3.0.0).","paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9e36b9e2858eef92b637abc885aedc7cc3a745511d9da85391c45da8f91e142e"}},{"note":"Executed by the postinstall script of troubleshooting@3.0.0.","paths":["beacon.cjs"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"}},{"source":"PACKAGE_ARCHIVE","digests":{"sha256":"a6b1f6c20b2ce88e11c467a0df7c8570b8d25c549aadd04affb37310647fc4b4"},"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@1.1.0).","paths":["package.json"]},{"paths":["beacon.cjs"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"},"note":"Executed by the postinstall script of troubleshooting@1.1.0."},{"digests":{"sha256":"28058651eb58dd8ce81d910e706ed48c15aeaf3b4a0c2ffe789ad329742f434f"},"note":"postinstall script runs `node beacon.cjs`, which POSTs hostname, install path and cwd to http://185.158.107.175:8787/_ah/dc (troubleshooting@2.0.1).","paths":["package.json"],"source":"PACKAGE_ARCHIVE"},{"note":"Executed by the postinstall script of troubleshooting@2.0.1.","paths":["beacon.cjs"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531"}}]},"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-021120","import_time":"2026-10-08T03:50:29.235704196Z","modified_time":"2026-10-08T03:38:56Z","sha256":"12b6f407e0af6cc239f1c478e20a35539c0fcfc55383b4c91bb28c8d761b6e0c"},{"import_time":"2026-10-08T03:50:29.516676825Z","modified_time":"2026-10-08T03:39:42Z","sha256":"1d90760032473b2d515d64b81a0a49c2c2721fe292e8202105b5c7ff2d9c62eb","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-021125"},{"import_time":"2026-10-08T03:50:29.406955779Z","modified_time":"2026-10-08T03:39:24Z","sha256":"28103a0b6203c0917551439eb348f6b197e382fad4e84d9bf2cbaadd48012ccb","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-021123"},{"modified_time":"2026-10-08T03:37:38Z","sha256":"2de8bb87c22c8d38bbe8802eda96645534386329c38faf8599659acd36f63f1f","source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-021111","import_time":"2026-10-08T03:50:28.586907761Z"},{"modified_time":"2026-10-08T03:39:58Z","sha256":"380314bcd4aa77f2a4ab4888c42977509fe75f3cd98dbaebfabee9c5802f94a3","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-021127","import_time":"2026-10-08T03:50:29.628697551Z"},{"id":"IN-MAL-2026-021122","import_time":"2026-10-08T03:50:29.342816973Z","modified_time":"2026-10-08T03:39:15Z","sha256":"3f72779e9bac9b888cd1ce0469e24b47bb787ab79a82ae0a48a7197921699469","source":"amazon-inspector","versions":["1.0.0"]},{"sha256":"528ab481d195c2bbda3a82684d945456dab74b48db46f90b5f65cb98b6d5a2ee","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-021102","import_time":"2026-10-08T03:50:28.00849661Z","modified_time":"2026-10-08T03:36:11Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/troubleshooting/v/99.0.1"}],"affected":[{"package":{"name":"troubleshooting","ecosystem":"npm","purl":"pkg:npm/troubleshooting"},"versions":["0.1.0","1.0.0","1.0.1","99.0.1","3.0.0","1.1.0","2.0.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"beacon.cjs","sha256":"9469c53670e67c2558a1cda35919a1cd8a44148b6697f639bbfeb6d1bef66531","tlsh":"363141eba8e1e0489aaa7098c54f1409f17bf4069501af54fd5c82955f6153c33fa8dc"},{"tlsh":"2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee","path":"index.js","sha256":"a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-B8uhPtSmrwNhV6Tvx0G4SpqwXnvq8G0dnje4l170FYNsBJUVUYljg4/b9N2hAbJWIjp59/cS5lMm8tK+quHR+Q==","sha1":"2d771f0fdac3bda213237ca3ecd4925885e016e4"},"filename":"troubleshooting-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/troubleshooting/MAL-2026-17641.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"InvisiRisk, Inc.","contact":["https://www.invisirisk.com","mailto:research@invisirisk.com"],"type":"FINDER"}]}