{"id":"MAL-2026-17698","summary":"Malicious code in @dransay/phone-fix-test (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08)\nPackage.json declares scripts.preinstall=\"node beacon.js\", which fires automatically on npm install. beacon.js performs a DNS lookup and HTTPS GET to a hardcoded Interactsh/OAST subdomain under oast.site, keyed on the package name, causing the installing host's source IP and resolver metadata to be logged by a non-first-party collector. The package is published under the @dransay scope on the public npm registry at version 99.0.0 — the standard dependency-confusion probe shape (scoped name matching a target organization, implausibly high version to win resolution against an internal package of the same name). Any build system that resolves @dransay/phone-fix-test from public npm will execute the preinstall callout and leak its network identifier to the researcher's OAST endpoint. The README self-labels the behavior as authorized security research, but a self-label does not change the installer-side effect: unconsented install-time exfiltration of host-identifying network metadata to a researcher-controlled collector.\n","modified":"2026-10-08T17:25:24.506179849Z","published":"2026-10-08T16:55:05Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-08T16:55:05Z","sha256":"e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08","source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-021219","import_time":"2026-10-08T17:17:19.55248728Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dransay/phone-fix-test/v/99.0.0"}],"affected":[{"package":{"name":"@dransay/phone-fix-test","ecosystem":"npm","purl":"pkg:npm/%40dransay/phone-fix-test"},"versions":["99.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"5dc2a8fab9b03b476d4dc0a1e0adec0f975bbf16b17967b8390ae78e96992329","tlsh":"011168ac07f42700b1e8f4a8848d11e94b73d164854a46c0f1cdc3ab5e5347c17674f7","path":"beacon.js"},{"sha256":"3dc54ac5fa10bce7e2048f9f9a14275e825cef5d0ba3db3c5d74244597028dad","tlsh":"64e0f1506b802e3700cc64f00d2c529792f3dd2e535d2d0891cb431f932d53553b715c","path":"package.json"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-AS1c+M78pNmZUH7O9rag0Hk5WPpqn2STcxWBsa85lQRsUFthN+KzHyL93t4aU3Uk53DJ14GL4mVGneKJULCnXg==","sha1":"b7fdc06abc2940455b48d5ffd1f3b4a9c5201def"},"filename":"phone-fix-test-99.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/phone-fix-test/MAL-2026-17698.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}