MAL-2026-17290

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-button-poc/MAL-2026-17290.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17290
Published
2026-09-29T22:11:06Z
Modified
2026-09-29T22:31:17Z
Summary
Malicious code in @rutxploit-sec/waves-button-poc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (435937e521ca52ff4d99fd276136aff40364c4a88a3a4677cecf390c9d9bb600)

@rutxploit-sec/waves-button-poc@1.0.0 auto-executes host-identifier exfiltration on both npm install and require. package.json declares a preinstall script that runs node -e code which reads os.hostname() and os.userInfo().username and issues a plaintext HTTP GET to the hardcoded bare-IP endpoint http://80.225.217.8/poc/dep-confusion-proof.html, passing the package name, host, and user as query parameters. The declared main entry index.js repeats the same behavior at module top level, so any consumer that requires the package also beacons the same identifiers to the same IP. The scoped name and PoC framing are consistent with a dependency-confusion proof-of-concept, but the shipped code performs unauthenticated identifier collection from every installer regardless of intent, and the destination is an attacker-chosen bare IP over cleartext HTTP.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020680",
            "import_time":  "2026-09-29T22:18:23.669688488Z",
            "modified_time":  "2026-09-29T22:11:17Z",
            "sha256":  "027441f2919ac3a1738060cf97928623de59aa32bb761d800511ddef988e4594",
            "source":  "amazon-inspector",
            "versions":  [
                "2.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020679",
            "import_time":  "2026-09-29T22:18:23.645760355Z",
            "modified_time":  "2026-09-29T22:11:06Z",
            "sha256":  "435937e521ca52ff4d99fd276136aff40364c4a88a3a4677cecf390c9d9bb600",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020681",
            "import_time":  "2026-09-29T22:18:23.701478928Z",
            "modified_time":  "2026-09-29T22:11:27Z",
            "sha256":  "492c9828b8988340ba8c92aca132634fa2ff4d21b9864c5e508b613ce5cc4c5c",
            "source":  "amazon-inspector",
            "versions":  [
                "3.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @rutxploit-sec/waves-button-poc

Package

Name
@rutxploit-sec/waves-button-poc
View open source insights on deps.dev
Purl
pkg:npm/%40rutxploit-sec/waves-button-poc

Affected ranges

Affected versions

1.*
1.0.0
2.*
2.0.0
3.*
3.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "f2d161e58653878754a14b39ea8cc82635d9b9b8179d70f0df655c5603708373",
            "tlsh":  "e9019ef84020d8376dca4159022be94bb2d64d874d612c199ad7794dc3d8a710a7faab"
        },
        {
            "path":  "index.js",
            "sha256":  "705552d22c839b650d8d73c9d163dc3e751430145718cfe5343866bb316d934d",
            "tlsh":  "cae02bfc00a4857c399a0144a657484f77e79f424d52cc11c9e5978bc7a0ee10e155b6"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "waves-button-poc-2.0.0.tgz",
            "hashes":  {
                "sha1":  "02f69610253233cf53d81de19b144a72f5be43d8",
                "sha512_sri":  "sha512-gudTCyMAEuqH7rHEYv/0foy9ahDkPMbsPqKUCniowPKJ2+eUBlYHQ9/QSVeNDAzhHE0bFD34TZ3xGgSxPL0+MA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-button-poc/MAL-2026-17290.json"