-= Per source details. Do not edit below this line.=-
The package declares a preinstall script that runs beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded Interactsh collector host (db3klhbi6i9hark1kegg174t38h33b6wt.oast.site) at npm install time. Both the DNS query and the HTTPS request embed the package name, so any machine that resolves and installs this scoped name sends an unsolicited out-of-band callback carrying the installing host's source IP, resolver identity, timing, and the internal package name to a third-party collector. The implausibly high 99.0.0 version against a scoped name is the dependency-confusion shape — the artifact is intended to win resolution against an internal @dransay/secrets and beacon from whichever build environment resolves it, disclosing internal network and build-system identity. No functional library code accompanies the beacon; the package's only on-install effect is the callback.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021218",
"import_time": "2026-10-08T17:17:19.515163388Z",
"modified_time": "2026-10-08T16:54:53Z",
"sha256": "aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "beacon.js",
"sha256": "c349b97633b914de05b90a5f3e2a89908f2527742ec54b89b9d98cdff30fc48e",
"tlsh": "481132a81af42b00b1e9b4a4988e11e84b73d1a8844a46c0f1cec3ab5e5347c17674fb"
}
],
"package_integrity": [
{
"filename": "secrets-99.0.0.tgz",
"hashes": {
"sha1": "0baa0bf39156a02d8337e0dbb6bc84058c0426ff",
"sha512_sri": "sha512-MlwVfk5JhL++bQCdDJ2NWh1U0CIhJfgsG7AMKZsmHIZa/7cHPPLyHOB93XZF5uIfOcnrqodOvDT2l0rEU3hxhg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/secrets/MAL-2026-17699.json"