Compatibility shim.
The install hook and package entrypoint transmit local machine and project identity details to an external host.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook runs beacon.cjs automatically during installation.
package.jsonView on unpkg · L7Source collects local host identity data and sends it to an external endpoint.
beacon.cjsView on unpkg · L3Source fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.cjsView on unpkgbeacon.cjs collects the machine hostname, install path, and current working directory.
beacon.cjsView on unpkg · L26beacon.cjs sends the collected payload in an HTTP POST to 185.158.107.175:8787.
beacon.cjsView on unpkg · L21Importing index.js also fires the beacon, while exporting no-op functions as a compatibility shim.
index.jsView on unpkg · L4This report applies to troubleshooting@99.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L7The postinstall hook runs beacon.cjs automatically during installation.
package.jsonView on unpkg · L7beacon.cjs sends the collected payload in an HTTP POST to 185.158.107.175:8787.
beacon.cjsView on unpkg · L21Source collects local host identity data and sends it to an external endpoint.
beacon.cjsView on unpkg · L3beacon.cjs collects the machine hostname, install path, and current working directory.
beacon.cjsView on unpkg · L26Source fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.cjsView on unpkgImporting index.js also fires the beacon, while exporting no-op functions as a compatibility shim.