Logo
npm

cat-sis2go-utils@99.1.0

Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 6:10 AM UTC

Malicious

OSV ID

MAL-2026-16071

Ecosystem

npm

Summary

Package cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.

Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.