Skip to main content

Malicious code in @cats-cdf/browser-metrics-meter (npm)

0
High
Published: 08/06/2026 (08/06/2026, 23:54:52 UTC)
Source: GCVE Database
Product: @cats-cdf/browser-metrics-meter

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.

Affected software

npmghsa
@cats-cdf/browser-metrics-meter
Affected versions
=3.1.1=2.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 09:01:00 UTC

Technical Analysis

The @cats-cdf/browser-metrics-meter npm package versions 3.1.1 and 2.0.0 include a preinstall script that executes commands to obtain the username (whoami), hostname, and public IP address (via ifconfig.me). These values are transmitted as query parameters over plain HTTP to a hardcoded external domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) using curl or wget. This domain is an out-of-band application security testing (OAST) collector, indicating the package performs unauthorized reconnaissance and data exfiltration during installation without any documented or legitimate purpose.

Potential Impact

The malicious preinstall script leaks sensitive system information including the username, hostname, and public IP address to an external attacker-controlled domain. This can lead to privacy violations and may facilitate further targeted attacks by revealing environment details. The data is transmitted in cleartext, increasing the risk of interception. There is no indication of further payload delivery or exploitation beyond this reconnaissance activity.

Mitigation Recommendations

No official patch or remediation is currently documented for this package. Users should avoid installing versions 3.1.1 and 2.0.0 of @cats-cdf/browser-metrics-meter. Consider removing these versions from any dependency trees and replacing them with trusted alternatives. Monitor for updates from the package maintainer or npm advisories for any future fixes. Since this is a malicious package behavior, reporting it to npm for takedown is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13479
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a757399bf8831d539d91a24

Added to database: 08/07/2026, 05:56:41 UTC

Last enriched: 08/07/2026, 09:01:00 UTC

Last updated: 09/21/2026, 22:47:08 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses