xblaxw@1.0.1
Malicious code in xblaxw (npm)
Analysis
xblaxw@1.0.1 is a "compatibility shim" package whose postinstall hook ("node beacon.cjs") beacons host metadata to a hardcoded IP address. beacon.cjs POSTs a JSON body containing the package name, hostname, install path, working directory and npm/node version to hxxp://185[.]158[.]107[.]175:8787/_ah/dc with an X-Beacon-Package: xblaxw header. index.js re-fires the same beacon whenever the package is required and exports a Proxy that returns no-op functions for any property access, so a project that merely imports the name silently triggers the callback without breaking the build. The package name is a combosquat-style shim intended to be pulled in as a dependency; the beacon endpoint is a bare IP with no legitimate service behind it. No credential, token or file contents are read or sent — the payload is limited to install/host fingerprinting reported to the remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 08:46 PM
- analyzed
- Oct 8, 2026, 10:03 PM
Related advisories
- xblaxw@1.0.0 same package
- xblaxw@1.1.0 same package
- xblaxw@99.0.1 same package
- wie888r@99.0.1
- @wxwxtest/testrrrdd@3.0.0
- @wxwxtest/testrrrdd@2.0.1
- @wxwxtest/testrrrdd@1.0.0
- @wxwxtest/testrrrdd@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.