{"id":"MAL-2026-17697","summary":"Malicious code in @dransay/logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85)\nThe package @dransay/logger@99.0.0 ships a preinstall hook (`node beacon.js`) that fires on `npm install`. The script performs a DNS lookup and HTTPS GET to the interactsh collaborator host `db3klhbi6i9hark1kegg174t38h33b6wt.oast.site`, encoding the package name in the subdomain/path. The version number (99.0.0) is implausibly high for a package with no release history, consistent with a dependency-confusion squat intended to win semver resolution against a private internal name. On install, the beacon discloses the installer's source IP, DNS resolver, and timestamp to a third-party host under the scoped name `@dransay/logger`, confirming successful resolution of this public package in an environment that may have intended to resolve a private `@dransay/*` package. No further payload is executed in this version, but the install-time callback to an attacker-controlled OAST endpoint is the reconnaissance stage of a dependency-confusion attack.\n","modified":"2026-10-08T17:25:24.520579598Z","published":"2026-10-08T16:54:45Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.0"],"id":"IN-MAL-2026-021217","import_time":"2026-10-08T17:17:19.484094692Z","modified_time":"2026-10-08T16:54:45Z","sha256":"5d4cbd17edce3b0c45619c9af869321807357e3dae1af8aa94835d3143185e85","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dransay/logger/v/99.0.0"}],"affected":[{"package":{"name":"@dransay/logger","ecosystem":"npm","purl":"pkg:npm/%40dransay/logger"},"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/logger/MAL-2026-17697.json","indicators":{"package_integrity":[{"filename":"logger-99.0.0.tgz","hashes":{"sha1":"7bed3312af9c237aa9a08cbff1bcd8e2d5db7c25","sha512_sri":"sha512-F9Y//cXkNsqdFcC+cGhtRG1T9T17KMPrRjFniAJg3U/fDUqYkUZN5BZ559x7blByXb5bCG897dpTPzXV5lHsBg=="}}],"evidence_files":[{"path":"beacon.js","sha256":"6d5bfbcce18f2b83bbf6db3a4b36b8ca8e35b0df507d344a8af0b0d132461ffb","tlsh":"931165ad0be42b00b1e8f4a4888e01e94b73d1a8844946c0f2cec3ab6e5347c17674fb"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}