-= Per source details. Do not edit below this line.=-
The package's preinstall lifecycle script runs automatically on npm install and executes whoami and hostname, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-016846",
"import_time": "2026-08-07T00:59:21.271160391Z",
"modified_time": "2026-08-06T23:54:52Z",
"sha256": "1617d21e0e87913cb47a2bdf2c2f9e010d8eb91de61b74e692ee8bac8299ba94",
"source": "amazon-inspector",
"versions": [
"3.1.1"
]
},
{
"id": "IN-MAL-2026-016848",
"import_time": "2026-08-07T00:59:21.45439328Z",
"modified_time": "2026-08-06T23:55:33Z",
"sha256": "83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8",
"source": "amazon-inspector",
"versions": [
"2.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "scripts/preinstall.js",
"sha256": "4275061552723f1d31253e74f931ebac93d9f83b772b3c68a53374c1b4c9dd68",
"tlsh": "6d01f9f7636553f04fc2cd96854eb58b5317a12a7502bca87cbd0a563b49c0c13f22d5"
}
],
"package_integrity": [
{
"filename": "browser-metrics-meter-3.1.1.tgz",
"hashes": {
"sha1": "323192f97e3145a22729bbfe83acba7f9665c887",
"sha512_sri": "sha512-9HtZuafPv3YNVJKH3VtFrrplxOqPi3SmI1BfmxSfR7Zo7PU3olunbogG3ezVIutw7P6iF4gLEg2fyBedKKDdCw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cats-cdf/browser-metrics-meter/MAL-2026-13479.json"