MAL-2026-17698

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/phone-fix-test/MAL-2026-17698.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17698
Published
2026-10-08T16:55:05Z
Modified
2026-10-08T17:25:24Z
Summary
Malicious code in @dransay/phone-fix-test (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08)

Package.json declares scripts.preinstall="node beacon.js", which fires automatically on npm install. beacon.js performs a DNS lookup and HTTPS GET to a hardcoded Interactsh/OAST subdomain under oast.site, keyed on the package name, causing the installing host's source IP and resolver metadata to be logged by a non-first-party collector. The package is published under the @dransay scope on the public npm registry at version 99.0.0 — the standard dependency-confusion probe shape (scoped name matching a target organization, implausibly high version to win resolution against an internal package of the same name). Any build system that resolves @dransay/phone-fix-test from public npm will execute the preinstall callout and leak its network identifier to the researcher's OAST endpoint. The README self-labels the behavior as authorized security research, but a self-label does not change the installer-side effect: unconsented install-time exfiltration of host-identifying network metadata to a researcher-controlled collector.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021219",
            "import_time": "2026-10-08T17:17:19.55248728Z",
            "modified_time": "2026-10-08T16:55:05Z",
            "sha256": "e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dransay/phone-fix-test

Package

Name
@dransay/phone-fix-test
View open source insights on deps.dev
Purl
pkg:npm/%40dransay/phone-fix-test

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.js",
            "sha256": "5dc2a8fab9b03b476d4dc0a1e0adec0f975bbf16b17967b8390ae78e96992329",
            "tlsh": "011168ac07f42700b1e8f4a8848d11e94b73d164854a46c0f1cdc3ab5e5347c17674f7"
        },
        {
            "path": "package.json",
            "sha256": "3dc54ac5fa10bce7e2048f9f9a14275e825cef5d0ba3db3c5d74244597028dad",
            "tlsh": "64e0f1506b802e3700cc64f00d2c529792f3dd2e535d2d0891cb431f932d53553b715c"
        }
    ],
    "package_integrity": [
        {
            "filename": "phone-fix-test-99.0.0.tgz",
            "hashes": {
                "sha1": "b7fdc06abc2940455b48d5ffd1f3b4a9c5201def",
                "sha512_sri": "sha512-AS1c+M78pNmZUH7O9rag0Hk5WPpqn2STcxWBsa85lQRsUFthN+KzHyL93t4aU3Uk53DJ14GL4mVGneKJULCnXg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/phone-fix-test/MAL-2026-17698.json"