OSV ID
MAL-2026-17700
Ecosystem
npm
Summary
dransay@99.0.0 declares a preinstall lifecycle script that runs node beacon.js, which performs a DNS lookup and HTTPS GET against a hardcoded Interactsh (oast.site) collaborator subdomain (db3klhbi6i9hark1kegg174t38h33b6wt.oast.site) on every npm install. The outbound request discloses the installer's source IP, DNS resolver IP, hostname-derived data, and timestamp to a third-party collaborator host unrelated to any first-party publisher. The package name and implausibly high version (99.0.0) are consistent with a dependency-confusion probe targeting an internal package name. The README self-labels the package as a benign dependency-confusion proof-of-concept; the self-label does not change the behavior — install-time, non-consensual outbound network I/O to a researcher-controlled OAST host that collects installer network identity.
Source: amazon-inspector (46d06d0ce82913346840f676660d67f9838f48511e58eef793bfe7c52091071f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.