Logo
npm

@dransay/feature-flags@99.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC

Malicious

OSV ID

MAL-2026-17696

Ecosystem

npm

Summary

@dransay/feature-flags@99.0.0 publishes a scoped name on the public npm registry at an inflated version (99.0.0) designed to win semver resolution against any private internal @dransay/* copy. package.json declares a preinstall hook node beacon.js; beacon.js unconditionally performs a DNS lookup and HTTPS GET to the hardcoded interactsh callback host db3klhbi6i9hark1kegg174t38h33b6wt.oast.site on every npm install, leaking the installer's public source IP, a timestamp, and confirmation that the scoped name resolved from the public registry to a third-party out-of-band interaction collector. The README self-describes the artifact as a probe of DrAnsay build infrastructure; author self-labeling as research does not change the install-time behavior for any environment whose npm resolves @dransay/* publicly.

Source: amazon-inspector (cc545bbb96903ee25218d8cab1a7d116d2ceb1ba64a3c929c79e56a6fc8e0585)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.