-= Per source details. Do not edit below this line.=-
Package cat-sis2go-utils@99.0.0 declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019843",
"import_time": "2026-09-09T05:40:09.19538336Z",
"modified_time": "2026-09-09T05:33:44Z",
"sha256": "205b59e55b3e3474f6b5de7471c11e7095e019a9f1e682083b34eeb7dddd5c3f",
"source": "amazon-inspector",
"versions": [
"99.1.0"
]
},
{
"id": "IN-MAL-2026-019845",
"import_time": "2026-09-09T05:40:09.252208812Z",
"modified_time": "2026-09-09T05:34:00Z",
"sha256": "ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "scripts/run.js",
"sha256": "0b598419ad8ba34a16ac19961d91208266d100dfed2598d298fbf9d5cb7eea2b",
"tlsh": "952103e648f581281ef342c0574bec5aa273da067546ee9076ac03321fc59fc9a739f8"
}
],
"package_integrity": [
{
"filename": "cat-sis2go-utils-99.1.0.tgz",
"hashes": {
"sha1": "49e87faf015f6773e543b29044c7ee396b20c85f",
"sha512_sri": "sha512-wx8JSI0n1stzrdeP3eUD9piuGQKVMbrB4/ZV/Ez1IaNUT+4EBXSmejvY64wx7xd9dQ43x60XN4i3msVUW3dr6A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json"