OpenSSF/OSV advisory MAL-2026-13479 confirms this npm version as malicious. The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @cats-cdf/browser-metrics-meter (npm)
Details
The package's preinstall lifecycle script runs automatically on `npm install` and executes `whoami` and `hostname`, then fetches the machine's public IP from ifconfig.me and transmits all three values as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP via curl, with a wget fallback. The domain is an OAST (out-of-band application security testing) collector used to receive exfiltrated reconnaissance data. The behavior fires unconditionally with no first-party relationship, no consent, and no documented purpose consistent with the package name.
Decision reason
OpenSSF Malicious Packages via OSV confirms @cats-cdf/browser-metrics-meter@3.1.1 as malicious (MAL-2026-13479): Malicious code in @cats-cdf/browser-metrics-meter (npm)