MAL-2026-17288

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-canny/MAL-2026-17288.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17288
Published
2026-09-29T22:11:37Z
Modified
2026-09-29T22:31:17Z
Summary
Malicious code in @rutxploit-sec/subsplash-canny (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (dc1ebadea2eb63a0fc7cf7446e36a589c5b87fc7d28e68b68145b98577107ebb)

npm package @rutxploit-sec/subsplash-canny declares a preinstall lifecycle script that runs node -e inline code reading os.hostname() and os.userInfo().username and issuing an HTTP GET to http://127.0.0.1:8099/ with those values as query parameters, plus a package identifier. The package.json description and README self-describe the artifact as a dependency-confusion proof-of-concept impersonating the private scoped name @subsplash/canny. Installing this package on any machine automatically executes the beacon at install time and transmits the installer's hostname and OS username to the configured endpoint. The current destination is loopback (127.0.0.1:8099), which limits real-world reach in this specific tarball, but the mechanism — arbitrary code execution and identity collection on npm install — is fully wired and would function identically against any remote endpoint.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020682",
            "import_time":  "2026-09-29T22:18:23.735732683Z",
            "modified_time":  "2026-09-29T22:11:37Z",
            "sha256":  "dc1ebadea2eb63a0fc7cf7446e36a589c5b87fc7d28e68b68145b98577107ebb",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @rutxploit-sec/subsplash-canny

Package

Name
@rutxploit-sec/subsplash-canny
View open source insights on deps.dev
Purl
pkg:npm/%40rutxploit-sec/subsplash-canny

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "1bc3cc6512e18fd7deb4ccead1597906e632252503785934cb3c60e03816afe0",
            "tlsh":  "f701f4f44110f4529d8d01b86a3f105bf5f1ef4681602c049ede140ccbd43f6096ea92"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "subsplash-canny-1.0.0.tgz",
            "hashes":  {
                "sha1":  "c30332e7583a93f4dcca05c4417e1d2ceb691744",
                "sha512_sri":  "sha512-6ONC8bP3VyFJd1iMjClObWjNbtiUK+V4MOE9M/h2xJ/0XBNo1tXObNl+qw4LwidrK5aRMrvtCOgsxybtuUB89w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-canny/MAL-2026-17288.json"