Logo
npm

content-common@99.9.9

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC

Malicious

OSV ID

MAL-2026-13442

Ecosystem

npm

Summary

content-common@99.9.9 declares a preinstall lifecycle script in package.json that executes node -e to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on npm install, confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.

Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.