MAL-2026-13479
Dashboard / Malicious Package / MAL-2026-13479
MAL-2026-13479
Summary: Malicious code in @cats-cdf/browser-metrics-meter (npm)
Details: Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
References: https://www.npmjs.com/package/@cats-cdf/browser-metrics-meter/v/3.1.1, https://www.npmjs.com/package/@cats-cdf/browser-metrics-meter/v/2.0.0
Affected packages
Package
Name: @cats-cdf/browser-metrics-meter
Purl: pkg:npm/%40cats-cdf/browser-metrics-meter
Affected ranges
Type: N/A
Events:
