-= Per source details. Do not edit below this line.=-
Package.json declares scripts.preinstall="node beacon.js", which fires automatically on npm install. beacon.js performs a DNS lookup and HTTPS GET to a hardcoded Interactsh/OAST subdomain under oast.site, keyed on the package name, causing the installing host's source IP and resolver metadata to be logged by a non-first-party collector. The package is published under the @dransay scope on the public npm registry at version 99.0.0 — the standard dependency-confusion probe shape (scoped name matching a target organization, implausibly high version to win resolution against an internal package of the same name). Any build system that resolves @dransay/phone-fix-test from public npm will execute the preinstall callout and leak its network identifier to the researcher's OAST endpoint. The README self-labels the behavior as authorized security research, but a self-label does not change the installer-side effect: unconsented install-time exfiltration of host-identifying network metadata to a researcher-controlled collector.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021219",
"import_time": "2026-10-08T17:17:19.55248728Z",
"modified_time": "2026-10-08T16:55:05Z",
"sha256": "e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.js",
"sha256": "5dc2a8fab9b03b476d4dc0a1e0adec0f975bbf16b17967b8390ae78e96992329",
"tlsh": "011168ac07f42700b1e8f4a8848d11e94b73d164854a46c0f1cdc3ab5e5347c17674f7"
},
{
"path": "package.json",
"sha256": "3dc54ac5fa10bce7e2048f9f9a14275e825cef5d0ba3db3c5d74244597028dad",
"tlsh": "64e0f1506b802e3700cc64f00d2c529792f3dd2e535d2d0891cb431f932d53553b715c"
}
],
"package_integrity": [
{
"filename": "phone-fix-test-99.0.0.tgz",
"hashes": {
"sha1": "b7fdc06abc2940455b48d5ffd1f3b4a9c5201def",
"sha512_sri": "sha512-AS1c+M78pNmZUH7O9rag0Hk5WPpqn2STcxWBsa85lQRsUFthN+KzHyL93t4aU3Uk53DJ14GL4mVGneKJULCnXg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/phone-fix-test/MAL-2026-17698.json"