MAL-2026-13479

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cats-cdf/browser-metrics-meter/MAL-2026-13479.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13479
Published
2026-08-06T23:54:52Z
Modified
2026-08-07T01:19:46Z
Summary
Malicious code in @cats-cdf/browser-metrics-meter (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8)

The package's preinstall lifecycle script runs automatically on npm install and executes whoami and hostname, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-016846",
            "import_time": "2026-08-07T00:59:21.271160391Z",
            "modified_time": "2026-08-06T23:54:52Z",
            "sha256": "1617d21e0e87913cb47a2bdf2c2f9e010d8eb91de61b74e692ee8bac8299ba94",
            "source": "amazon-inspector",
            "versions": [
                "3.1.1"
            ]
        },
        {
            "id": "IN-MAL-2026-016848",
            "import_time": "2026-08-07T00:59:21.45439328Z",
            "modified_time": "2026-08-06T23:55:33Z",
            "sha256": "83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @cats-cdf/browser-metrics-meter

Package

Name
@cats-cdf/browser-metrics-meter
View open source insights on deps.dev
Purl
pkg:npm/%40cats-cdf/browser-metrics-meter

Affected ranges

Affected versions

2.*
2.0.0
3.*
3.1.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "scripts/preinstall.js",
            "sha256": "4275061552723f1d31253e74f931ebac93d9f83b772b3c68a53374c1b4c9dd68",
            "tlsh": "6d01f9f7636553f04fc2cd96854eb58b5317a12a7502bca87cbd0a563b49c0c13f22d5"
        }
    ],
    "package_integrity": [
        {
            "filename": "browser-metrics-meter-3.1.1.tgz",
            "hashes": {
                "sha1": "323192f97e3145a22729bbfe83acba7f9665c887",
                "sha512_sri": "sha512-9HtZuafPv3YNVJKH3VtFrrplxOqPi3SmI1BfmxSfR7Zo7PU3olunbogG3ezVIutw7P6iF4gLEg2fyBedKKDdCw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cats-cdf/browser-metrics-meter/MAL-2026-13479.json"