@dransay/phone-fix-test@99.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:45 PM UTC
OSV ID
MAL-2026-17698
Ecosystem
npm
Summary
Package.json declares scripts.preinstall="node beacon.js", which fires automatically on npm install. beacon.js performs a DNS lookup and HTTPS GET to a hardcoded Interactsh/OAST subdomain under oast.site, keyed on the package name, causing the installing host's source IP and resolver metadata to be logged by a non-first-party collector. The package is published under the @dransay scope on the public npm registry at version 99.0.0 — the standard dependency-confusion probe shape (scoped name matching a target organization, implausibly high version to win resolution against an internal package of the same name). Any build system that resolves @dransay/phone-fix-test from public npm will execute the preinstall callout and leak its network identifier to the researcher's OAST endpoint. The README self-labels the behavior as authorized security research, but a self-label does not change the installer-side effect: unconsented install-time exfiltration of host-identifying network metadata to a researcher-controlled collector.
Source: amazon-inspector (e01479e9a6af5de5f6abec6c16007bd3757b52b0e434b38b44d40fde12961c08)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.