Skip to main content

Malicious code in @cats-cdf/authentication (npm)

0
High
Published: 08/06/2026 (08/06/2026, 23:55:20 UTC)
Source: GCVE Database
Product: @cats-cdf/authentication

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (404569337a1e5fc46fff2584e052d2f9f99c3cb8d04e5fb3b5c5d633c178e01c) The package's preinstall lifecycle script runs on npm install and collects the installer's local username (whoami), hostname, and public IP address (fetched via ifconfig.me), then transmits them as query-string parameters in an HTTP GET request to a hardcoded subdomain of oast.fun (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun). oast.fun is an out-of-band interaction/callback service commonly used for reconnaissance and exfiltration in dependency-confusion attacks. The behavior fires automatically on default install with no relation to any documented package purpose.

Affected software

npmghsa
@cats-cdf/authentication
Affected versions
=3.1.1=2.17.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 09:00:50 UTC

Technical Analysis

The @cats-cdf/authentication npm package versions 3.1.1 and 2.17.1 include a malicious preinstall script that executes during installation. The script collects sensitive environment information—specifically the installer's local username (via whoami), hostname, and public IP address (queried from ifconfig.me)—and transmits these details as query parameters in an HTTP GET request to a hardcoded subdomain of oast.fun. The domain oast.fun is known for facilitating out-of-band interactions used in reconnaissance and exfiltration, particularly in dependency confusion attacks. This exfiltration occurs automatically without user interaction or relation to the package's intended functionality.

Potential Impact

The malicious preinstall script leaks sensitive environment information including the local username, hostname, and public IP address of the system performing the npm install. This information disclosure can aid attackers in reconnaissance and potentially facilitate further targeted attacks such as dependency confusion or supply chain compromise. There is no indication of active exploitation in the wild at this time.

Mitigation Recommendations

No official patch or remediation guidance is provided in the available data. Users should avoid installing the affected versions (=3.1.1 and =2.17.1) of the @cats-cdf/authentication package. Review and audit dependencies before installation, and consider using package integrity verification tools or alternative trusted packages. Monitor vendor advisories for updates or patches addressing this malicious behavior.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13478
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a757399bf8831d539d91a28

Added to database: 08/07/2026, 05:56:41 UTC

Last enriched: 08/07/2026, 09:00:50 UTC

Last updated: 09/22/2026, 06:26:50 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses