@dransay/secrets@99.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17699
Ecosystem
npm
Summary
The package declares a preinstall script that runs beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded Interactsh collector host (db3klhbi6i9hark1kegg174t38h33b6wt.oast.site) at npm install time. Both the DNS query and the HTTPS request embed the package name, so any machine that resolves and installs this scoped name sends an unsolicited out-of-band callback carrying the installing host's source IP, resolver identity, timing, and the internal package name to a third-party collector. The implausibly high 99.0.0 version against a scoped name is the dependency-confusion shape — the artifact is intended to win resolution against an internal @dransay/secrets and beacon from whichever build environment resolves it, disclosing internal network and build-system identity. No functional library code accompanies the beacon; the package's only on-install effect is the callback.
Source: amazon-inspector (aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.