{"id":"MAL-2026-17704","summary":"Malicious code in @wxwxtest/testrrrdd (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34)\nThe package ships a postinstall script (`scripts.postinstall` runs `node beacon.cjs`) and a top-level `require('./beacon.cjs').fire()` in `index.js` that POST installer host metadata — hostname, install path, cwd, Node version, and package name — to the hardcoded plain-HTTP bare-IP endpoint `http://185.158.107.175:8787/_ah/dc`. The exfiltration fires automatically both on `npm install` and on any `require()` of the package. `index.js` otherwise exports a Proxy returning no-op functions for any property access, so the package has no legitimate functionality; its sole effect is the callback to the hardcoded endpoint. The destination is not associated with any publisher domain and is unrelated to the self-described 'compatibility shim' purpose. The shape (stub Proxy export + install/require-time beacon to a bare-IP collector) is a dependency-confusion / typosquat proof-of-installation beacon.\n","modified":"2026-10-08T21:45:48.342129953Z","published":"2026-10-08T21:21:17Z","database_specific":{"malicious-packages-origins":[{"versions":["2.0.1"],"id":"IN-MAL-2026-021268","import_time":"2026-10-08T21:42:57.762614731Z","modified_time":"2026-10-08T21:23:51Z","sha256":"093f62f129fa3bb6fb05829e930449393d54a9d5e72a5188aaa542a26b0ce368","source":"amazon-inspector"},{"id":"IN-MAL-2026-021252","import_time":"2026-10-08T21:42:56.519207066Z","modified_time":"2026-10-08T21:21:34Z","sha256":"4a04b2b4f02f5d06a3729f210aa1ec9844c54ad8b1653677fc6e3d62e7f18549","source":"amazon-inspector","versions":["2.0.0"]},{"id":"IN-MAL-2026-021253","import_time":"2026-10-08T21:42:56.623622268Z","modified_time":"2026-10-08T21:21:42Z","sha256":"73ce932992891761028144293d7b2e414208fee2695adccf3d09bbd8751f3f79","source":"amazon-inspector","versions":["0.0.1"]},{"modified_time":"2026-10-08T21:22:00Z","sha256":"e194808ec33e50a585181e38b0359bd1f04e848fd87aa06c6bca80bbde2a50a7","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-021255","import_time":"2026-10-08T21:42:56.780389011Z"},{"versions":["0.1.0"],"id":"IN-MAL-2026-021251","import_time":"2026-10-08T21:42:56.457783297Z","modified_time":"2026-10-08T21:21:26Z","sha256":"e7fce4d8536bf6254aa0791b2d048874ea7cc153303b68e28aa7e296493b342e","source":"amazon-inspector"},{"modified_time":"2026-10-08T21:23:58Z","sha256":"0e87a3919d1aeb1d6b9f3069d72f5098fe92fbafc821448753dc650745ff0f62","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021269","import_time":"2026-10-08T21:42:57.845095126Z"},{"import_time":"2026-10-08T21:42:56.358827821Z","modified_time":"2026-10-08T21:21:17Z","sha256":"2c288e48135ebe9f305d450f5b19324ae944865fb7057ced986d0eb30cb1fe34","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-021250"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/2.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/0.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wxwxtest/testrrrdd/v/1.0.1"}],"affected":[{"package":{"name":"@wxwxtest/testrrrdd","ecosystem":"npm","purl":"pkg:npm/%40wxwxtest/testrrrdd"},"versions":["2.0.1","2.0.0","0.0.1","3.0.0","0.1.0","1.0.0","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"f15a8241a11d830a39d4a0aa33a42d8a61d5a80c","sha512_sri":"sha512-oZCcmW2AH5v1a7iMachtLDnfIVWvO2xnVOibjbAuMDtV4BSo+jr3XyQW8moa1MyMWrxL8NWa3yJHB2J3RuUatA=="},"filename":"testrrrdd-2.0.1.tgz"}],"evidence_files":[{"sha256":"b90b0687de31609c4a0ed88db0d1979d33b510ec8e772abc2102b169766f09e7","tlsh":"3f3161eba8f1a0489aa77098c54f0409f17bf0068401ab50f95c82955f6153c33fa8dc","path":"beacon.cjs"},{"path":"index.js","sha256":"a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d","tlsh":"2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wxwxtest/testrrrdd/MAL-2026-17704.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}