{"id":"MAL-2026-17708","summary":"Malicious code in xblaxw (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2d2e0b35582727d314517ea66b234f665258076783678cdf645075a7294a0aed)\nxblaxw@1.1.0 is a stub package whose only behavior is a beacon. The package.json postinstall script runs `node beacon.cjs`, which collects host identifiers (hostname, install path, process.cwd(), process.version) and POSTs them as JSON to the hardcoded bare-IP endpoint http://185.158.107.175:8787/_ah/dc over plaintext HTTP. The same beacon is re-fired on require(): index.js exports a Proxy that returns a no-op function for any property access and calls require('./beacon.cjs').fire() on load, so the exfiltration also triggers whenever a consumer imports the package. The package description is 'Compatibility shim.' with no real functionality — the Proxy-of-noops export is consistent with a dependency-confusion / name-squat beacon designed to confirm which internal names resolve to this public package and report back installer host metadata to the operator at 185.158.107.175:8787.\n","modified":"2026-10-08T21:45:54.261495414Z","published":"2026-10-08T21:19:20Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-021236","import_time":"2026-10-08T21:42:55.246922945Z","modified_time":"2026-10-08T21:19:20Z","sha256":"110314989632807fad14e5fd2256199e22923b20df9f841ef8cce1480f13a693"},{"id":"IN-MAL-2026-021241","import_time":"2026-10-08T21:42:55.661724691Z","modified_time":"2026-10-08T21:20:02Z","sha256":"992dbd421e3f64461b699aa41190af6729174ecf2a179e5986aa8c638bea4ba7","source":"amazon-inspector","versions":["1.0.1"]},{"modified_time":"2026-10-08T21:23:29Z","sha256":"a67740f8c8fac71eb25c053bf07b93f3bc7b699aca1889831c2d64633e4f9d45","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-021265","import_time":"2026-10-08T21:42:57.54914459Z"},{"modified_time":"2026-10-08T21:19:52Z","sha256":"cc6a7f374924e3a4dc464dff2a51b6e916645280b776768d77fce9b0cd060045","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021240","import_time":"2026-10-08T21:42:55.57240259Z"},{"versions":["2.0.1"],"id":"IN-MAL-2026-021244","import_time":"2026-10-08T21:42:55.864824696Z","modified_time":"2026-10-08T21:20:27Z","sha256":"e92f858a6d813c2230dd5be0f27dba62ea7a966f1993443ebdd319b6d2a6da2c","source":"amazon-inspector"},{"sha256":"19bf74581564f1973f91f22b5ec0c562ba39e57b339306745910dba75f3a9367","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-021242","import_time":"2026-10-08T21:42:55.743016201Z","modified_time":"2026-10-08T21:20:09Z"},{"versions":["1.1.0"],"id":"IN-MAL-2026-021243","import_time":"2026-10-08T21:42:55.804275513Z","modified_time":"2026-10-08T21:20:17Z","sha256":"2d2e0b35582727d314517ea66b234f665258076783678cdf645075a7294a0aed","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/2.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/xblaxw/v/1.1.0"}],"affected":[{"package":{"name":"xblaxw","ecosystem":"npm","purl":"pkg:npm/xblaxw"},"versions":["2.0.0","1.0.1","99.0.1","1.0.0","2.0.1","3.0.0","1.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"xblaxw-2.0.0.tgz","hashes":{"sha512_sri":"sha512-Ms4jzKOM6QhgbT2ocpg4gWEl6sOFpEpgqVHxk5FNZ0s3eo375LcQV95VtGYpJCaBrwWGO0VIVQSeY3+TMj5vDg==","sha1":"2ccb9289a71752b71ab3b25e95109f500d5b1f20"}}],"evidence_files":[{"path":"beacon.cjs","sha256":"d8ec492e8a5266515bc6103067a07f98dc8644824089b9d32a14a435f43812ea","tlsh":"73314feba8e1a048aaab7098c54f1409b27bf4069501ab50f95c82959f6193c37fa8dc"},{"path":"index.js","sha256":"a86a4da763bbb34c16f361abe7aab66d5df591b66867ac8160041f932159b08d","tlsh":"2201d0d7225661b10b5221a4978f43c4a3b99d74027941d0d84a9226365108c463b8ee"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xblaxw/MAL-2026-17708.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}