Logo
npm

@dransay/secrets@99.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC

Malicious

OSV ID

MAL-2026-17699

Ecosystem

npm

Summary

The package declares a preinstall script that runs beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded Interactsh collector host (db3klhbi6i9hark1kegg174t38h33b6wt.oast.site) at npm install time. Both the DNS query and the HTTPS request embed the package name, so any machine that resolves and installs this scoped name sends an unsolicited out-of-band callback carrying the installing host's source IP, resolver identity, timing, and the internal package name to a third-party collector. The implausibly high 99.0.0 version against a scoped name is the dependency-confusion shape — the artifact is intended to win resolution against an internal @dransay/secrets and beacon from whichever build environment resolves it, disclosing internal network and build-system identity. No functional library code accompanies the beacon; the package's only on-install effect is the callback.

Source: amazon-inspector (aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.