-= Per source details. Do not edit below this line.=-
@rutxploit-sec/waves-button-poc@1.0.0 auto-executes host-identifier exfiltration on both npm install and require. package.json declares a preinstall script that runs node -e code which reads os.hostname() and os.userInfo().username and issues a plaintext HTTP GET to the hardcoded bare-IP endpoint http://80.225.217.8/poc/dep-confusion-proof.html, passing the package name, host, and user as query parameters. The declared main entry index.js repeats the same behavior at module top level, so any consumer that requires the package also beacons the same identifiers to the same IP. The scoped name and PoC framing are consistent with a dependency-confusion proof-of-concept, but the shipped code performs unauthenticated identifier collection from every installer regardless of intent, and the destination is an attacker-chosen bare IP over cleartext HTTP.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020680",
"import_time": "2026-09-29T22:18:23.669688488Z",
"modified_time": "2026-09-29T22:11:17Z",
"sha256": "027441f2919ac3a1738060cf97928623de59aa32bb761d800511ddef988e4594",
"source": "amazon-inspector",
"versions": [
"2.0.0"
]
},
{
"id": "IN-MAL-2026-020679",
"import_time": "2026-09-29T22:18:23.645760355Z",
"modified_time": "2026-09-29T22:11:06Z",
"sha256": "435937e521ca52ff4d99fd276136aff40364c4a88a3a4677cecf390c9d9bb600",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-020681",
"import_time": "2026-09-29T22:18:23.701478928Z",
"modified_time": "2026-09-29T22:11:27Z",
"sha256": "492c9828b8988340ba8c92aca132634fa2ff4d21b9864c5e508b613ce5cc4c5c",
"source": "amazon-inspector",
"versions": [
"3.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "f2d161e58653878754a14b39ea8cc82635d9b9b8179d70f0df655c5603708373",
"tlsh": "e9019ef84020d8376dca4159022be94bb2d64d874d612c199ad7794dc3d8a710a7faab"
},
{
"path": "index.js",
"sha256": "705552d22c839b650d8d73c9d163dc3e751430145718cfe5343866bb316d934d",
"tlsh": "cae02bfc00a4857c399a0144a657484f77e79f424d52cc11c9e5978bc7a0ee10e155b6"
}
],
"package_integrity": [
{
"filename": "waves-button-poc-2.0.0.tgz",
"hashes": {
"sha1": "02f69610253233cf53d81de19b144a72f5be43d8",
"sha512_sri": "sha512-gudTCyMAEuqH7rHEYv/0foy9ahDkPMbsPqKUCniowPKJ2+eUBlYHQ9/QSVeNDAzhHE0bFD34TZ3xGgSxPL0+MA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-button-poc/MAL-2026-17290.json"