MAL-2026-16071

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-16071
Published
2026-09-09T05:33:44Z
Modified
2026-09-09T05:45:04Z
Summary
Malicious code in cat-sis2go-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91)

Package cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-019843",
            "import_time": "2026-09-09T05:40:09.19538336Z",
            "modified_time": "2026-09-09T05:33:44Z",
            "sha256": "205b59e55b3e3474f6b5de7471c11e7095e019a9f1e682083b34eeb7dddd5c3f",
            "source": "amazon-inspector",
            "versions": [
                "99.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-019845",
            "import_time": "2026-09-09T05:40:09.252208812Z",
            "modified_time": "2026-09-09T05:34:00Z",
            "sha256": "ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / cat-sis2go-utils

Package

Name
cat-sis2go-utils
View open source insights on deps.dev
Purl
pkg:npm/cat-sis2go-utils

Affected ranges

Affected versions

99.*
99.0.0
99.1.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "scripts/run.js",
            "sha256": "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b",
            "tlsh": "952103e648f581281ef342c0574bec5aa273da067546ee9076ac03321fc59fc9a739f8"
        }
    ],
    "package_integrity": [
        {
            "filename": "cat-sis2go-utils-99.1.0.tgz",
            "hashes": {
                "sha1": "49e87faf015f6773e543b29044c7ee396b20c85f",
                "sha512_sri": "sha512-wx8JSI0n1stzrdeP3eUD9piuGQKVMbrB4/ZV/Ez1IaNUT+4EBXSmejvY64wx7xd9dQ43x60XN4i3msVUW3dr6A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json"