@dransay/feature-flags@99.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:45 PM UTC
OSV ID
MAL-2026-17696
Ecosystem
npm
Summary
@dransay/feature-flags@99.0.0 publishes a scoped name on the public npm registry at an inflated version (99.0.0) designed to win semver resolution against any private internal @dransay/* copy. package.json declares a preinstall hook node beacon.js; beacon.js unconditionally performs a DNS lookup and HTTPS GET to the hardcoded interactsh callback host db3klhbi6i9hark1kegg174t38h33b6wt.oast.site on every npm install, leaking the installer's public source IP, a timestamp, and confirmation that the scoped name resolved from the public registry to a third-party out-of-band interaction collector. The README self-describes the artifact as a probe of DrAnsay build infrastructure; author self-labeling as research does not change the install-time behavior for any environment whose npm resolves @dransay/* publicly.
Source: amazon-inspector (cc545bbb96903ee25218d8cab1a7d116d2ceb1ba64a3c929c79e56a6fc8e0585)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.