{"id":"MAL-2026-17668","summary":"Malicious code in @dransay/address-validation (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (189df4f2830e64a9cfbd0bed6ae8357aff16dc5496d83c3e5e4bd9457b536fa7)\n@dransay/address-validation@99.0.0 declares a preinstall script (`node beacon.js`) that fires on `npm install` and performs a DNS lookup plus HTTPS GET to a subdomain of the Interactsh collaborator service `oast.site` with the path `/address-validation`. The implausibly high version number (99.0.0) and the preinstall callback are consistent with a dependency-confusion probe: any environment resolving this name reveals its egress IP and the package name to the operator of the collaborator host. No installer secrets, environment variables, or filesystem contents are read; the beacon transmits only install metadata (source IP, package name, DNS resolver). No code is fetched or executed from the remote host, and no persistence is established.\n\n## Source: ossf-package-analysis (82ababa5637b2f53f5087a161eeba1b6ca6ddba6d31ebb7842614bf0da119fa7)\nThe OpenSSF Package Analysis project identified '@dransay/address-validation' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-10-08T17:25:24.582190216Z","published":"2026-10-08T08:46:02Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.0"],"import_time":"2026-10-08T08:52:39.514186189Z","modified_time":"2026-10-08T08:46:02Z","sha256":"82ababa5637b2f53f5087a161eeba1b6ca6ddba6d31ebb7842614bf0da119fa7","source":"ossf-package-analysis"},{"source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-021214","import_time":"2026-10-08T17:17:19.367879884Z","modified_time":"2026-10-08T16:54:22Z","sha256":"189df4f2830e64a9cfbd0bed6ae8357aff16dc5496d83c3e5e4bd9457b536fa7"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dransay/address-validation/v/99.0.0"}],"affected":[{"package":{"name":"@dransay/address-validation","ecosystem":"npm","purl":"pkg:npm/%40dransay/address-validation"},"versions":["99.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"beacon.js","sha256":"56ca0c591ea77746ba3e98ce67ebc889aa08cd6cd9780df2ada894e1093de2d0","tlsh":"261132ad4ae42b00b1e9b4a488ce01e94b73d1a8844946c0e1cec3ab5fa347c17674fb"}],"package_integrity":[{"filename":"address-validation-99.0.0.tgz","hashes":{"sha1":"6377b5dbde9b77352830bbf6923966c6fc105b2f","sha512_sri":"sha512-M0+bLPsCYkHSUOBFLBZnT77+1dyGczp6mmLdC6cqd49aTom9pfFrHjNqXqG3Z9Vt3F4tU1qlasXNlFzHQi9Uzw=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/address-validation/MAL-2026-17668.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}