MAL-2026-17289

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-google-tag-manager/MAL-2026-17289.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17289
Published
2026-09-29T22:11:49Z
Modified
2026-09-29T22:31:17Z
Summary
Malicious code in @rutxploit-sec/subsplash-google-tag-manager (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8fe2c746dc5c09bc67257fd4eba671824806c9080b7ca94949e45175deb03b8d)

package.json declares a preinstall script that executes inline Node code reading os.hostname() and os.userInfo().username and issuing an HTTP GET to http://127.0.0.1:8099/ carrying those identifiers along with the impersonated package name. The package is published under @rutxploit-sec but its manifest description and index.js console output identify it as representing the private scope @subsplash/google-tag-manager, and any installer whose resolver picks this public name over the intended private package will execute the preinstall code and disclose hostname and username. The beacon destination in this artifact is loopback (127.0.0.1:8099), consistent with a proof-of-concept collector rather than a live external C2, but the install-time execution primitive and dependency-confusion targeting are the full attack shape.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020683",
            "import_time":  "2026-09-29T22:18:23.760750178Z",
            "modified_time":  "2026-09-29T22:11:49Z",
            "sha256":  "8fe2c746dc5c09bc67257fd4eba671824806c9080b7ca94949e45175deb03b8d",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @rutxploit-sec/subsplash-google-tag-manager

Package

Name
@rutxploit-sec/subsplash-google-tag-manager
View open source insights on deps.dev
Purl
pkg:npm/%40rutxploit-sec/subsplash-google-tag-manager

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "426cb2c3e09d6eb5493e46cfa09013b295446eca60506227aa44b98df64b864c",
            "tlsh":  "e70190f6d318f4375ece0175663a101bb2f78f4784a06c70abee181c87963f61526ad2"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "subsplash-google-tag-manager-1.0.0.tgz",
            "hashes":  {
                "sha1":  "3638dd8c85fea6215d5ee33b0f1e53ce187aaa4d",
                "sha512_sri":  "sha512-nx94YmFAYVfYVDku/AfaFEA8RkVYEk8Y6eIZ0duI5GfWtl93Ern7pPtmlAZ4nuVB4KaCqxWFEksKQLNli8fBrg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-google-tag-manager/MAL-2026-17289.json"