{"id":"MAL-2026-17700","summary":"Malicious code in dransay (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (46d06d0ce82913346840f676660d67f9838f48511e58eef793bfe7c52091071f)\ndransay@99.0.0 declares a `preinstall` lifecycle script that runs `node beacon.js`, which performs a DNS lookup and HTTPS GET against a hardcoded Interactsh (`oast.site`) collaborator subdomain (`db3klhbi6i9hark1kegg174t38h33b6wt.oast.site`) on every `npm install`. The outbound request discloses the installer's source IP, DNS resolver IP, hostname-derived data, and timestamp to a third-party collaborator host unrelated to any first-party publisher. The package name and implausibly high version (99.0.0) are consistent with a dependency-confusion probe targeting an internal package name. The README self-labels the package as a benign dependency-confusion proof-of-concept; the self-label does not change the behavior — install-time, non-consensual outbound network I/O to a researcher-controlled OAST host that collects installer network identity.\n","modified":"2026-10-08T18:00:04.454470393Z","published":"2026-10-08T17:23:01Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-021227","import_time":"2026-10-08T17:43:20.188351321Z","modified_time":"2026-10-08T17:23:01Z","sha256":"46d06d0ce82913346840f676660d67f9838f48511e58eef793bfe7c52091071f"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dransay/v/99.0.0"}],"affected":[{"package":{"name":"dransay","ecosystem":"npm","purl":"pkg:npm/dransay"},"versions":["99.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"dransay-99.0.0.tgz","hashes":{"sha1":"aca0769ba477e971d3dd231bc9914cbeede8dda1","sha512_sri":"sha512-Za78JrpJOW8wN1gBxjRfMcvJGWFYRTdHvOFTEfhuoh1bbh7ruvfRLBJLFnUrnr3uxNjWWUStvE36oPMXS0ITLw=="}}],"evidence_files":[{"tlsh":"451168ad56e42700b1e9f45494cd01e84b73d1a4844946c0f1cec39b5e5347d17674f7","path":"beacon.js","sha256":"def65592785337a3ce4a18e0af15acf013ab32c97a3b6c390d2782dbb458fe1c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dransay/MAL-2026-17700.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}