VDB
KO

MAL-2026-13479

Malicious code in @cats-cdf/browser-metrics-meter (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (83df5c7e17dd2b9a808bddee17deb157e88a12632a632177f7969fce9ccfa7a8) The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @cats-cdf/browser-metrics-meter

No fixed version published yet for @cats-cdf/browser-metrics-meter (npm). Pin to a known-safe version or switch to an alternative.

References