{"id":"MAL-2026-17699","summary":"Malicious code in @dransay/secrets (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51)\nThe package declares a `preinstall` script that runs `beacon.js`, which performs a DNS lookup and HTTPS GET to a hardcoded Interactsh collector host (`db3klhbi6i9hark1kegg174t38h33b6wt.oast.site`) at `npm install` time. Both the DNS query and the HTTPS request embed the package name, so any machine that resolves and installs this scoped name sends an unsolicited out-of-band callback carrying the installing host's source IP, resolver identity, timing, and the internal package name to a third-party collector. The implausibly high `99.0.0` version against a scoped name is the dependency-confusion shape — the artifact is intended to win resolution against an internal `@dransay/secrets` and beacon from whichever build environment resolves it, disclosing internal network and build-system identity. No functional library code accompanies the beacon; the package's only on-install effect is the callback.\n","modified":"2026-10-08T17:25:24.510298309Z","published":"2026-10-08T16:54:53Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-08T17:17:19.515163388Z","modified_time":"2026-10-08T16:54:53Z","sha256":"aef0f6b36413e45664391c5341f7c30a4501c2cc916add9ba6525bf57e559d51","source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-021218"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dransay/secrets/v/99.0.0"}],"affected":[{"package":{"name":"@dransay/secrets","ecosystem":"npm","purl":"pkg:npm/%40dransay/secrets"},"versions":["99.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"481132a81af42b00b1e9b4a4988e11e84b73d1a8844a46c0f1cec3ab5e5347c17674fb","path":"beacon.js","sha256":"c349b97633b914de05b90a5f3e2a89908f2527742ec54b89b9d98cdff30fc48e"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-MlwVfk5JhL++bQCdDJ2NWh1U0CIhJfgsG7AMKZsmHIZa/7cHPPLyHOB93XZF5uIfOcnrqodOvDT2l0rEU3hxhg==","sha1":"0baa0bf39156a02d8337e0dbb6bc84058c0426ff"},"filename":"secrets-99.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dransay/secrets/MAL-2026-17699.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}