Malicious code in @cats-cdf/browser-metrics-meter (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
AI Analysis
Technical Summary
The @cats-cdf/browser-metrics-meter npm package versions 3.1.1 and 2.0.0 include a preinstall script that executes commands to obtain the username (whoami), hostname, and public IP address (via ifconfig.me). These values are transmitted as query parameters over plain HTTP to a hardcoded external domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) using curl or wget. This domain is an out-of-band application security testing (OAST) collector, indicating the package performs unauthorized reconnaissance and data exfiltration during installation without any documented or legitimate purpose.
Potential Impact
The malicious preinstall script leaks sensitive system information including the username, hostname, and public IP address to an external attacker-controlled domain. This can lead to privacy violations and may facilitate further targeted attacks by revealing environment details. The data is transmitted in cleartext, increasing the risk of interception. There is no indication of further payload delivery or exploitation beyond this reconnaissance activity.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing versions 3.1.1 and 2.0.0 of @cats-cdf/browser-metrics-meter. Consider removing these versions from any dependency trees and replacing them with trusted alternatives. Monitor for updates from the package maintainer or npm advisories for any future fixes. Since this is a malicious package behavior, reporting it to npm for takedown is recommended.
Malicious code in @cats-cdf/browser-metrics-meter (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @cats-cdf/browser-metrics-meter npm package versions 3.1.1 and 2.0.0 include a preinstall script that executes commands to obtain the username (whoami), hostname, and public IP address (via ifconfig.me). These values are transmitted as query parameters over plain HTTP to a hardcoded external domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) using curl or wget. This domain is an out-of-band application security testing (OAST) collector, indicating the package performs unauthorized reconnaissance and data exfiltration during installation without any documented or legitimate purpose.
Potential Impact
The malicious preinstall script leaks sensitive system information including the username, hostname, and public IP address to an external attacker-controlled domain. This can lead to privacy violations and may facilitate further targeted attacks by revealing environment details. The data is transmitted in cleartext, increasing the risk of interception. There is no indication of further payload delivery or exploitation beyond this reconnaissance activity.
Mitigation Recommendations
No official patch or remediation is currently documented for this package. Users should avoid installing versions 3.1.1 and 2.0.0 of @cats-cdf/browser-metrics-meter. Consider removing these versions from any dependency trees and replacing them with trusted alternatives. Monitor for updates from the package maintainer or npm advisories for any future fixes. Since this is a malicious package behavior, reporting it to npm for takedown is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13479
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a757399bf8831d539d91a24
Added to database: 08/07/2026, 05:56:41 UTC
Last enriched: 08/07/2026, 09:01:00 UTC
Last updated: 09/21/2026, 22:47:08 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.