OpenSSF/OSV advisory MAL-2026-1809 confirms this npm version as malicious. The package is a stub whose index.js exports a Proxy returning no-op functions for every property access, so consumers that import it receive a non-functional module. The only functional code is beacon.cjs, which POSTs the installer's hostname, install path (__dirname), cwd, and Node version as JSON to the hardcoded bare-IP plain-HTTP endpoint http://185.158.107.175:8787/_ah/dc...
This report applies to ph-common@1.0.0.
0.1.0, 1.0.0, 1.0.1, 1.1.0, 2.0.0, 2.0.1, 3.0.0, 77.7.7, 99.0.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.