-= Per source details. Do not edit below this line.=-
On npm install, the package's preinstall hook executes beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded interactsh (OAST) subdomain under oast.site, embedding the package name in the path. The implausibly high version number (99.0.0) combined with the generic scope-plus-name is the canonical shape of a dependency-confusion probe: publish a public package reusing an internal name at a version high enough to win resolution, and record every host that resolves it. Each install leaks the installer's egress IP and the fact that an internal-named package was pulled from the public registry to a third-party-controlled collector, confirming to the operator that the target organization is exploitable for a follow-on malicious release under the same name. No installer secrets, environment variables, or filesystem contents are read, and no remote code is executed from the response, but the beacon itself materializes attacker benefit (reconnaissance of vulnerable internal names) at install time.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021216",
"import_time": "2026-10-08T17:17:19.458804625Z",
"modified_time": "2026-10-08T16:54:37Z",
"sha256": "dc3d55a63787b5f45312d0b8433f6e782b2a6b28e89ef6377e24e5d26c757a61",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.js",
"sha256": "0cd9afa4808217e8686a3cfa514b9d22d7b3eb8cfa7e33a51326a0d9b84dcb17",
"tlsh": "6f1165ac0ae42b00b1e8f4a4888e01e84b73d1a8844946c0f2cec3ab5e5347c17674fb"
}
],
"package_integrity": [
{
"filename": "db-99.0.0.tgz",
"hashes": {
"sha1": "e2187ad013e576c05de9c3d018da521c88c0ac17",
"sha512_sri": "sha512-G3PjRwIxfqXaOYaOQoOZI7MWgFb1vpL2NH6F/IYzvfVhqODTqMpWWg9fLZpOGqAKOnFCxk+SswZsBhDDCwKFsQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/db/MAL-2026-17695.json"