Logo
npm

@dransay/logger@99.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC

Malicious

OSV ID

MAL-2026-17697

Ecosystem

npm

Summary

The package @dransay/logger@99.0.0 ships a preinstall hook (node beacon.js) that fires on npm install. The script performs a DNS lookup and HTTPS GET to the interactsh collaborator host db3klhbi6i9hark1kegg174t38h33b6wt.oast.site, encoding the package name in the subdomain/path. The version number (99.0.0) is implausibly high for a package with no release history, consistent with a dependency-confusion squat intended to win semver resolution against a private internal name. On install, the beacon discloses the installer's source IP, DNS resolver, and timestamp to a third-party host under the scoped name @dransay/logger, confirming successful resolution of this public package in an environment that may have intended to resolve a private @dransay/* package. No further payload is executed in this version, but the install-time callback to an attacker-controlled OAST endpoint is the reconnaissance stage of a dependency-confusion attack.

Source: amazon-inspector (5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.