xblaxw@1.1.0
Malicious code in xblaxw (npm)
Analysis
xblaxw@1.1.0 ships a postinstall hook ("node beacon.cjs") that runs automatically on npm install with no opt-in. beacon.cjs collects machine and install metadata — the host hostname, the package install path (__dirname), the current working directory, and the npm/node user-agent string — and POSTs it as JSON to the hardcoded endpoint hxxp://185[.]158[.]107[.]175:8787/_ah/dc with the header X-Beacon-Package: xblaxw. The request is sent over plain HTTP to a raw IP address, is retried, and network errors are silently swallowed so the install appears to succeed. The package's stated purpose ("Compatibility shim.") requires no network activity, and the beacon's own comment claims it reports "only machine/package metadata" while providing no repository or research provenance. This is an install-time host-fingerprinting beacon phoning home to a hardcoded C2 address.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 08:46 PM
- analyzed
- Oct 8, 2026, 09:17 PM
Related advisories
- xblaxw@1.0.1 same package
- xblaxw@1.0.0 same package
- xblaxw@99.0.1 same package
- wie888r@99.0.1
- @wxwxtest/testrrrdd@3.0.0
- @wxwxtest/testrrrdd@2.0.1
- @wxwxtest/testrrrdd@1.0.0
- @wxwxtest/testrrrdd@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.