content-common@99.9.9
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC
OSV ID
MAL-2026-13442
Ecosystem
npm
Summary
content-common@99.9.9 declares a preinstall lifecycle script in package.json that executes node -e to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on npm install, confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.
Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.