content-common @99.9.9
Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC
OSV ID
MAL-2026-13442
Ecosystem
npm
Summary
content-common@99.9.9 declares a preinstall lifecycle script in package.json that executes node -e to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on npm install , confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.
Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.