Malicious code in @cats-cdf/browser-metrics-meter (npm)
The npm package @cats-cdf/browser-metrics-meter contained malicious code in its preinstall lifecycle script that exfiltrated system reconnaissance data (username, hostname, public IP) to an OAST collector domain. The package executed this behavior unconditionally on installation without consent or documented purpose.
- Disclosed
- Last updated
- Blast radius
- Any developer or system that installed the malicious package via npm install
- Ecosystems
- Attack vectors
- Affected entities
- @cats-cdf/browser-metrics-meter
The npm package @cats-cdf/browser-metrics-meter was found to contain malicious code embedded in its preinstall lifecycle script. Upon installation via npm install, the script automatically executed commands to gather system reconnaissance information.\n\nThe malicious script executed whoami and hostname commands, then fetched the machine's public IP address from ifconfig.me. All three values were transmitted as query-string parameters to a hardcoded out-of-band interaction domain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun) over plain HTTP using curl, with wget as a fallback mechanism.\n\nThe target domain is an OAST (out-of-band application security testing) collector designed to receive exfiltrated reconnaissance data. The malicious behavior executed unconditionally with no first-party relationship, user consent, or documented purpose consistent with the package's stated function as a browser metrics meter.\n\nThe incident was identified and credited to the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- @cats-cdf/browser-metrics-meter
- Domains
- kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun
Remediation
- Remove the @cats-cdf/browser-metrics-meter package from all projects and dependencies
- Audit npm install logs and package-lock.json files to identify when the malicious package was installed
- Assume any system that installed this package may have had credentials or sensitive information exposed; review access logs for affected systems
- Update to a clean version of the package if a legitimate replacement is available, or use an alternative package
- Consider implementing npm package verification and scanning tools in your CI/CD pipeline to detect malicious packages before installation
- Review firewall and network logs for any outbound connections to kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun or similar OAST domains
Sources
- GitHub Advisory GHSA-c4hf-jrgf-gw89 · GitHub Advisory Database
Cite this entry
"Malicious code in @cats-cdf/browser-metrics-meter (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-cats-cdf-browser-metrics-meter-npm-usbfgg
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in epic-common (npm)
The npm package epic-common was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in checkout-desktop-total (npm)
The npm package checkout-desktop-total contained malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under wel1.ru. Any system that imported this package should be considered compromised.
npmCompromised package - activecritical
Malware in @zizie071/libsignal-node
The npm package @zizie071/libsignal-node contains malware that grants full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit