MAL-2026-17695

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/db/MAL-2026-17695.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17695
Published
2026-10-08T16:54:37Z
Modified
2026-10-08T17:25:24Z
Summary
Malicious code in @dransay/db (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (dc3d55a63787b5f45312d0b8433f6e782b2a6b28e89ef6377e24e5d26c757a61)

On npm install, the package's preinstall hook executes beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded interactsh (OAST) subdomain under oast.site, embedding the package name in the path. The implausibly high version number (99.0.0) combined with the generic scope-plus-name is the canonical shape of a dependency-confusion probe: publish a public package reusing an internal name at a version high enough to win resolution, and record every host that resolves it. Each install leaks the installer's egress IP and the fact that an internal-named package was pulled from the public registry to a third-party-controlled collector, confirming to the operator that the target organization is exploitable for a follow-on malicious release under the same name. No installer secrets, environment variables, or filesystem contents are read, and no remote code is executed from the response, but the beacon itself materializes attacker benefit (reconnaissance of vulnerable internal names) at install time.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021216",
            "import_time": "2026-10-08T17:17:19.458804625Z",
            "modified_time": "2026-10-08T16:54:37Z",
            "sha256": "dc3d55a63787b5f45312d0b8433f6e782b2a6b28e89ef6377e24e5d26c757a61",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dransay/db

Package

Name
@dransay/db
View open source insights on deps.dev
Purl
pkg:npm/%40dransay/db

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.js",
            "sha256": "0cd9afa4808217e8686a3cfa514b9d22d7b3eb8cfa7e33a51326a0d9b84dcb17",
            "tlsh": "6f1165ac0ae42b00b1e8f4a4888e01e84b73d1a8844946c0f2cec3ab5e5347c17674fb"
        }
    ],
    "package_integrity": [
        {
            "filename": "db-99.0.0.tgz",
            "hashes": {
                "sha1": "e2187ad013e576c05de9c3d018da521c88c0ac17",
                "sha512_sri": "sha512-G3PjRwIxfqXaOYaOQoOZI7MWgFb1vpL2NH6F/IYzvfVhqODTqMpWWg9fLZpOGqAKOnFCxk+SswZsBhDDCwKFsQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/db/MAL-2026-17695.json"