-= Per source details. Do not edit below this line.=-
@dransay/address-validation@99.0.0 declares a preinstall script (node beacon.js) that fires on npm install and performs a DNS lookup plus HTTPS GET to a subdomain of the Interactsh collaborator service oast.site with the path /address-validation. The implausibly high version number (99.0.0) and the preinstall callback are consistent with a dependency-confusion probe: any environment resolving this name reveals its egress IP and the package name to the operator of the collaborator host. No installer secrets, environment variables, or filesystem contents are read; the beacon transmits only install metadata (source IP, package name, DNS resolver). No code is fetched or executed from the remote host, and no persistence is established.
The OpenSSF Package Analysis project identified '@dransay/address-validation' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-10-08T08:52:39.514186189Z",
"modified_time": "2026-10-08T08:46:02Z",
"sha256": "82ababa5637b2f53f5087a161eeba1b6ca6ddba6d31ebb7842614bf0da119fa7",
"source": "ossf-package-analysis",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-021214",
"import_time": "2026-10-08T17:17:19.367879884Z",
"modified_time": "2026-10-08T16:54:22Z",
"sha256": "189df4f2830e64a9cfbd0bed6ae8357aff16dc5496d83c3e5e4bd9457b536fa7",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.js",
"sha256": "56ca0c591ea77746ba3e98ce67ebc889aa08cd6cd9780df2ada894e1093de2d0",
"tlsh": "261132ad4ae42b00b1e9b4a488ce01e94b73d1a8844946c0e1cec3ab5fa347c17674fb"
}
],
"package_integrity": [
{
"filename": "address-validation-99.0.0.tgz",
"hashes": {
"sha1": "6377b5dbde9b77352830bbf6923966c6fc105b2f",
"sha512_sri": "sha512-M0+bLPsCYkHSUOBFLBZnT77+1dyGczp6mmLdC6cqd49aTom9pfFrHjNqXqG3Z9Vt3F4tU1qlasXNlFzHQi9Uzw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/address-validation/MAL-2026-17668.json"