@cats-cdf/browser-metrics-meter @3.1.1
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 10:11 AM UTC
OSV ID
MAL-2026-13479
Ecosystem
npm
Summary
The package's preinstall lifecycle script runs automatically on npm install and executes whoami and hostname , then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.