MAL-2026-17699

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/secrets/MAL-2026-17699.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17699
Published
2026-10-08T16:54:53Z
Modified
2026-10-08T17:25:24Z
Summary
Malicious code in @dransay/secrets (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51)

The package declares a preinstall script that runs beacon.js, which performs a DNS lookup and HTTPS GET to a hardcoded Interactsh collector host (db3klhbi6i9hark1kegg174t38h33b6wt.oast.site) at npm install time. Both the DNS query and the HTTPS request embed the package name, so any machine that resolves and installs this scoped name sends an unsolicited out-of-band callback carrying the installing host's source IP, resolver identity, timing, and the internal package name to a third-party collector. The implausibly high 99.0.0 version against a scoped name is the dependency-confusion shape — the artifact is intended to win resolution against an internal @dransay/secrets and beacon from whichever build environment resolves it, disclosing internal network and build-system identity. No functional library code accompanies the beacon; the package's only on-install effect is the callback.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021218",
            "import_time": "2026-10-08T17:17:19.515163388Z",
            "modified_time": "2026-10-08T16:54:53Z",
            "sha256": "aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dransay/secrets

Package

Name
@dransay/secrets
View open source insights on deps.dev
Purl
pkg:npm/%40dransay/secrets

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "beacon.js",
            "sha256": "c349b97633b914de05b90a5f3e2a89908f2527742ec54b89b9d98cdff30fc48e",
            "tlsh": "481132a81af42b00b1e9b4a4988e11e84b73d1a8844a46c0f1cec3ab5e5347c17674fb"
        }
    ],
    "package_integrity": [
        {
            "filename": "secrets-99.0.0.tgz",
            "hashes": {
                "sha1": "0baa0bf39156a02d8337e0dbb6bc84058c0426ff",
                "sha512_sri": "sha512-MlwVfk5JhL++bQCdDJ2NWh1U0CIhJfgsG7AMKZsmHIZa/7cHPPLyHOB93XZF5uIfOcnrqodOvDT2l0rEU3hxhg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/secrets/MAL-2026-17699.json"