MAL-2026-17697

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/logger/MAL-2026-17697.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17697
Published
2026-10-08T16:54:45Z
Modified
2026-10-08T17:25:24Z
Summary
Malicious code in @dransay/logger (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85)

The package @dransay/logger@99.0.0 ships a preinstall hook (node beacon.js) that fires on npm install. The script performs a DNS lookup and HTTPS GET to the interactsh collaborator host db3klhbi6i9hark1kegg174t38h33b6wt.oast.site, encoding the package name in the subdomain/path. The version number (99.0.0) is implausibly high for a package with no release history, consistent with a dependency-confusion squat intended to win semver resolution against a private internal name. On install, the beacon discloses the installer's source IP, DNS resolver, and timestamp to a third-party host under the scoped name @dransay/logger, confirming successful resolution of this public package in an environment that may have intended to resolve a private @dransay/* package. No further payload is executed in this version, but the install-time callback to an attacker-controlled OAST endpoint is the reconnaissance stage of a dependency-confusion attack.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021217",
            "import_time": "2026-10-08T17:17:19.484094692Z",
            "modified_time": "2026-10-08T16:54:45Z",
            "sha256": "5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dransay/logger

Package

Name
@dransay/logger
View open source insights on deps.dev
Purl
pkg:npm/%40dransay/logger

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.js",
            "sha256": "6d5bfbcce18f2b83bbf6db3a4b36b8ca8e35b0df507d344a8af0b0d132461ffb",
            "tlsh": "931165ad0be42b00b1e8f4a4888e01e94b73d1a8844946c0f2cec3ab6e5347c17674fb"
        }
    ],
    "package_integrity": [
        {
            "filename": "logger-99.0.0.tgz",
            "hashes": {
                "sha1": "7bed3312af9c237aa9a08cbff1bcd8e2d5db7c25",
                "sha512_sri": "sha512-F9Y//cXkNsqdFcC+cGhtRG1T9T17KMPrRjFniAJg3U/fDUqYkUZN5BZ559x7blByXb5bCG897dpTPzXV5lHsBg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/logger/MAL-2026-17697.json"