@dransay/db@99.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17695
Ecosystem
npm
Summary
On npm install, the package's preinstall hook executes beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded interactsh (OAST) subdomain under oast.site, embedding the package name in the path. The implausibly high version number (99.0.0) combined with the generic scope-plus-name is the canonical shape of a dependency-confusion probe: publish a public package reusing an internal name at a version high enough to win resolution, and record every host that resolves it. Each install leaks the installer's egress IP and the fact that an internal-named package was pulled from the public registry to a third-party-controlled collector, confirming to the operator that the target organization is exploitable for a follow-on malicious release under the same name. No installer secrets, environment variables, or filesystem contents are read, and no remote code is executed from the response, but the beacon itself materializes attacker benefit (reconnaissance of vulnerable internal names) at install time.
Source: amazon-inspector (dc3d55a63787b5f45312d0b8433f6e782b2a6b28e89ef6377e24e5d26c757a61)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.