{"id":"MAL-2026-17706","summary":"Malicious code in testrrrd (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad)\nOn `npm install`, package.json `scripts.postinstall` runs `node beacon.cjs`, which POSTs a JSON payload containing the installer's hostname (`os.hostname()`), install path (`__dirname`), current working directory (`process.cwd()`), Node version, and package identifier over plain HTTP to the hardcoded bare-IP endpoint `http://185.158.107.175:8787/_ah/dc`. The same beacon is re-triggered at import time: `index.js` (the declared `main`) calls `require('./beacon.cjs').fire()` and then exports a `Proxy` whose `get` trap returns a no-op for any member access, so consumers importing arbitrary names from the package continue past the callback. The dual trigger ensures the callback fires even when lifecycle scripts are suppressed (e.g. `npm install --ignore-scripts`), and the Proxy shim conceals that the package provides no legitimate functionality. The destination is a bare IPv4 address on a non-standard port unrelated to any declared publisher, and the transport is unencrypted.\n","modified":"2026-10-08T21:45:54.252488544Z","published":"2026-10-08T21:22:08Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-08T21:22:42Z","sha256":"016351de268cd01a6a8f3cb2278b3735206e45c254b3b166c18bc0bf4abf17b6","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021260","import_time":"2026-10-08T21:42:57.173961022Z"},{"source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-021257","import_time":"2026-10-08T21:42:56.965709286Z","modified_time":"2026-10-08T21:22:15Z","sha256":"84a7f8fd9d6de2f68ce889aa54d7492bbb2f7a4ac7c78542b27bb41cbb119a34"},{"sha256":"91a77cc9dbdff4799414082dc85fc6581b9f2d7297136dea8c50540f7d5244ad","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-021259","import_time":"2026-10-08T21:42:57.095468254Z","modified_time":"2026-10-08T21:22:32Z"},{"sha256":"e94d33713dfab2a5d24334bd4dfc9f840fe8357174a540134724097d9da92156","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-021267","import_time":"2026-10-08T21:42:57.702053496Z","modified_time":"2026-10-08T21:23:45Z"},{"sha256":"f3acddc2a24a30fe2bbb66b02f5da938bb888824a127915df5c86faec95ffe10","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-021258","import_time":"2026-10-08T21:42:57.027994051Z","modified_time":"2026-10-08T21:22:24Z"},{"modified_time":"2026-10-08T21:22:08Z","sha256":"0b2b8898408042377780b7012071a760128d4fcd83d0a3230cd1619036b427ed","source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-021256","import_time":"2026-10-08T21:42:56.84348094Z"},{"sha256":"767b0c5bd1f7cbd076d5564c333485255f96fe58c834757cf73d5d25c8d5c911","source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-021266","import_time":"2026-10-08T21:42:57.621688314Z","modified_time":"2026-10-08T21:23:37Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/0.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/testrrrd/v/2.0.0"}],"affected":[{"package":{"name":"testrrrd","ecosystem":"npm","purl":"pkg:npm/testrrrd"},"versions":["1.0.0","0.0.1","3.0.0","99.0.1","2.0.1","1.1.0","2.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"d8316feba8e1a008aaab7098c54f0409b27af0068401ab50f95c82959f6193c33fa8dc","path":"beacon.cjs","sha256":"e2b8e936f7052e6459566e71c32ecd56ec6cfdf468a892ecc4ca0cf8081bc6c7"},{"sha256":"d04d3f709eae18877d31d2e7296e5741dd596cd4d84e981edce12ccd14749d51","tlsh":"68d0a72089215e6364c56ee20e666e0a55a20d7f01147c083397505c46ed77729ff36d","path":"package.json"}],"package_integrity":[{"filename":"testrrrd-1.0.0.tgz","hashes":{"sha1":"6a61d105b73e3f5ffef00ef4ca8d22856342170d","sha512_sri":"sha512-G0aEuFlr3YlzNAsWANv887cXY9mfHTgrvaaOC28UIMDLSp1pOH5hhO+LZhzyCzmhHcFI1bEaiVnLLE1sRcbQUQ=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testrrrd/MAL-2026-17706.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}