MAL-2026-13479

    Dashboard / Malicious Package / MAL-2026-13479

    MAL-2026-13479

    Published: 6 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in @cats-cdf/browser-metrics-meter (npm)

    Details: Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.

    Affected packages

    Package

    Name: @cats-cdf/browser-metrics-meter

    Purl: pkg:npm/%40cats-cdf/browser-metrics-meter

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.1.1
    MAL-2026-13479 | CVE-DB