{"id":"MAL-2026-16071","summary":"Malicious code in cat-sis2go-utils (npm)","details":"cat-sis2go-utils is a dependency-confusion package published against the SIS2GO namespace, with versions inflated to 99.0.0 and 99.1.0. It ships no library code (index.js is an 87-byte stub), and package.json declares both preinstall and postinstall running `node scripts/run.js`, so the payload executes twice during npm install before any application code. The script resolves a DNS canary and POSTs to a webhook.site collector; 99.1.0 additionally sends os.userInfo().username and os.hostname(). The author labels this a PoC, but the beacon fires on any install that resolves the package and exfiltrates a username usable for follow-on attacks, and dependency-confusion packages require incident response even when trivial.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91)\nPackage cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.\n","modified":"2026-09-10T07:45:05.081005595Z","published":"2026-09-09T05:33:44Z","database_specific":{"malicious-packages-origins":[{"versions":["99.1.0"],"id":"IN-MAL-2026-019843","import_time":"2026-09-09T05:40:09.19538336Z","modified_time":"2026-09-09T05:33:44Z","sha256":"205b59e55b3e3474f6b5de7471c11e7095e019a9f1e682083b34eeb7dddd5c3f","source":"amazon-inspector"},{"id":"IN-MAL-2026-019845","import_time":"2026-09-09T05:40:09.252208812Z","modified_time":"2026-09-09T05:34:00Z","sha256":"ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91","source":"amazon-inspector","versions":["99.0.0"]}],"iocs":{"urls":["https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7"],"domains":["d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site"],"files":[{"paths":["index.js"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"0897440200959313ca1e8735d8d1524f70a0bddcde66778ecd46c0bb4981981f"},"note":"Present in versions 99.0.0 and 99.1.0."},{"source":"PACKAGE_ARCHIVE","digests":{"sha256":"91b460b9612ce51d74cb187bcf1793bd115255b117e5ca5858075c3a90b6b2b9"},"note":"Present in version 99.0.0.","paths":["package.json"]},{"digests":{"sha256":"b0ccdc7aaba664b0b4da3f317d06789d4cda2473f50c37a1c13264389130d6d7"},"note":"Present in version 99.0.0.","paths":["scripts/run.js"],"source":"PACKAGE_ARCHIVE"},{"note":"Present in version 99.1.0.","paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"0e3e6be9b193ff4b3e6bd60bc0bfe1d97b9f1c2d73d8fa2d731597b00b8501c1"}},{"digests":{"sha256":"0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b"},"note":"Present in version 99.1.0.","paths":["scripts/run.js"],"source":"PACKAGE_ARCHIVE"}]}},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cat-sis2go-utils/v/99.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/cat-sis2go-utils/v/99.0.0"}],"affected":[{"package":{"name":"cat-sis2go-utils","ecosystem":"npm","purl":"pkg:npm/cat-sis2go-utils"},"versions":["99.1.0","99.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b","tlsh":"952103e648f581281ef342c0574bec5aa273da067546ee9076ac03321fc59fc9a739f8","path":"scripts/run.js"}],"package_integrity":[{"hashes":{"sha1":"49e87faf015f6773e543b29044c7ee396b20c85f","sha512_sri":"sha512-wx8JSI0n1stzrdeP3eUD9piuGQKVMbrB4/ZV/Ez1IaNUT+4EBXSmejvY64wx7xd9dQ43x60XN4i3msVUW3dr6A=="},"filename":"cat-sis2go-utils-99.1.0.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"smilinghyena4","contact":["mailto:smilinghyena4@gmail.com"],"type":"FINDER"}]}