VYPR

npm · Malicious package advisory

Malware

cat-sis2go-utils

GHSA-h64p-6fgg-pgm9

Malicious code in cat-sis2go-utils (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.1.0`

## Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91)
Package [email protected] declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7539b1ad9a1ad0233b10c77e9bf3641af4696134/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7539b1ad9a1ad0233b10c77e9bf3641af4696134/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json
- https://www.npmjs.com/package/cat-sis2go-utils/v/99.0.0
- https://www.npmjs.com/package/cat-sis2go-utils/v/99.1.0
- https://github.com/ossf/malicious-packages/blob/98837fe030be0120d987d875c613818ea003002d/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json
- https://github.com/advisories/GHSA-h64p-6fgg-pgm9

Compromised versions (1)

  • = 99.1.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.