npm · Malicious package advisory
Malwarecat-sis2go-utils
GHSA-h64p-6fgg-pgm9
Malicious code in cat-sis2go-utils (npm)
Details
**Severity:** Critical **Affected versions:** `= 99.1.0` ## Source: amazon-inspector (ad357542f3dd0e1b598ef36d440b1868ac28c6889226864bf799b2f7b6bf5e91) Package [email protected] declares both preinstall and postinstall lifecycle hooks in package.json that execute scripts/run.js on every npm install. The script unconditionally issues a DNS lookup against d22d92dc-84e5-4b58-8cd6-75bf1ac452c7.dnshook.site and POSTs a JSON beacon containing the installer's hostname and process context to https://webhook.site/d22d92dc-84e5-4b58-8cd6-75bf1ac452c7. The package description self-identifies as a dependency-confusion PoC, and the 99.0.0 version is consistent with a resolution-winning squat targeting an internal package name. Installing the package results in arbitrary code execution on the installer host and fingerprints the machine to third-party out-of-band collectors under the operator's control. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7539b1ad9a1ad0233b10c77e9bf3641af4696134/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json)) **References:** - https://github.com/ossf/malicious-packages/blob/7539b1ad9a1ad0233b10c77e9bf3641af4696134/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json - https://www.npmjs.com/package/cat-sis2go-utils/v/99.0.0 - https://www.npmjs.com/package/cat-sis2go-utils/v/99.1.0 - https://github.com/ossf/malicious-packages/blob/98837fe030be0120d987d875c613818ea003002d/osv/malicious/npm/cat-sis2go-utils/MAL-2026-16071.json - https://github.com/advisories/GHSA-h64p-6fgg-pgm9
Compromised versions (1)
- = 99.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.