-= Per source details. Do not edit below this line.=-
The package @dransay/logger@99.0.0 ships a preinstall hook (node beacon.js) that fires on npm install. The script performs a DNS lookup and HTTPS GET to the interactsh collaborator host db3klhbi6i9hark1kegg174t38h33b6wt.oast.site, encoding the package name in the subdomain/path. The version number (99.0.0) is implausibly high for a package with no release history, consistent with a dependency-confusion squat intended to win semver resolution against a private internal name. On install, the beacon discloses the installer's source IP, DNS resolver, and timestamp to a third-party host under the scoped name @dransay/logger, confirming successful resolution of this public package in an environment that may have intended to resolve a private @dransay/* package. No further payload is executed in this version, but the install-time callback to an attacker-controlled OAST endpoint is the reconnaissance stage of a dependency-confusion attack.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021217",
"import_time": "2026-10-08T17:17:19.484094692Z",
"modified_time": "2026-10-08T16:54:45Z",
"sha256": "5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.js",
"sha256": "6d5bfbcce18f2b83bbf6db3a4b36b8ca8e35b0df507d344a8af0b0d132461ffb",
"tlsh": "931165ad0be42b00b1e8f4a4888e01e94b73d1a8844946c0f2cec3ab6e5347c17674fb"
}
],
"package_integrity": [
{
"filename": "logger-99.0.0.tgz",
"hashes": {
"sha1": "7bed3312af9c237aa9a08cbff1bcd8e2d5db7c25",
"sha512_sri": "sha512-F9Y//cXkNsqdFcC+cGhtRG1T9T17KMPrRjFniAJg3U/fDUqYkUZN5BZ559x7blByXb5bCG897dpTPzXV5lHsBg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/logger/MAL-2026-17697.json"