Malicious code in @cats-cdf/authentication (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (404569337a1e5fc46fff2584e052d2f9f99c3cb8d04e5fb3b5c5d633c178e01c) The package's preinstall lifecycle script runs on npm install and collects the installer's local username (whoami), hostname, and public IP address (fetched via ifconfig.me), then transmits them as query-string parameters in an HTTP GET request to a hardcoded subdomain of oast.fun (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun). oast.fun is an out-of-band interaction/callback service commonly used for reconnaissance and exfiltration in dependency-confusion attacks. The behavior fires automatically on default install with no relation to any documented package purpose.
AI Analysis
Technical Summary
The @cats-cdf/authentication npm package versions 3.1.1 and 2.17.1 include a malicious preinstall script that executes during installation. The script collects sensitive environment information—specifically the installer's local username (via whoami), hostname, and public IP address (queried from ifconfig.me)—and transmits these details as query parameters in an HTTP GET request to a hardcoded subdomain of oast.fun. The domain oast.fun is known for facilitating out-of-band interactions used in reconnaissance and exfiltration, particularly in dependency confusion attacks. This exfiltration occurs automatically without user interaction or relation to the package's intended functionality.
Potential Impact
The malicious preinstall script leaks sensitive environment information including the local username, hostname, and public IP address of the system performing the npm install. This information disclosure can aid attackers in reconnaissance and potentially facilitate further targeted attacks such as dependency confusion or supply chain compromise. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should avoid installing the affected versions (=3.1.1 and =2.17.1) of the @cats-cdf/authentication package. Review and audit dependencies before installation, and consider using package integrity verification tools or alternative trusted packages. Monitor vendor advisories for updates or patches addressing this malicious behavior.
Malicious code in @cats-cdf/authentication (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (404569337a1e5fc46fff2584e052d2f9f99c3cb8d04e5fb3b5c5d633c178e01c) The package's preinstall lifecycle script runs on npm install and collects the installer's local username (whoami), hostname, and public IP address (fetched via ifconfig.me), then transmits them as query-string parameters in an HTTP GET request to a hardcoded subdomain of oast.fun (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun). oast.fun is an out-of-band interaction/callback service commonly used for reconnaissance and exfiltration in dependency-confusion attacks. The behavior fires automatically on default install with no relation to any documented package purpose.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @cats-cdf/authentication npm package versions 3.1.1 and 2.17.1 include a malicious preinstall script that executes during installation. The script collects sensitive environment information—specifically the installer's local username (via whoami), hostname, and public IP address (queried from ifconfig.me)—and transmits these details as query parameters in an HTTP GET request to a hardcoded subdomain of oast.fun. The domain oast.fun is known for facilitating out-of-band interactions used in reconnaissance and exfiltration, particularly in dependency confusion attacks. This exfiltration occurs automatically without user interaction or relation to the package's intended functionality.
Potential Impact
The malicious preinstall script leaks sensitive environment information including the local username, hostname, and public IP address of the system performing the npm install. This information disclosure can aid attackers in reconnaissance and potentially facilitate further targeted attacks such as dependency confusion or supply chain compromise. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Users should avoid installing the affected versions (=3.1.1 and =2.17.1) of the @cats-cdf/authentication package. Review and audit dependencies before installation, and consider using package integrity verification tools or alternative trusted packages. Monitor vendor advisories for updates or patches addressing this malicious behavior.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13478
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a757399bf8831d539d91a28
Added to database: 08/07/2026, 05:56:41 UTC
Last enriched: 08/07/2026, 09:00:50 UTC
Last updated: 09/22/2026, 06:26:50 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.