MAL-2026-17291

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-icons/MAL-2026-17291.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17291
Published
2026-09-29T22:11:59Z
Modified
2026-09-29T22:31:17Z
Summary
Malicious code in @rutxploit-sec/waves-icons (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (bdeb076eee35958fd0520e7f9cca9d361c47f02cb81c73288609ecdfb60bdbb1)

@rutxploit-sec/waves-icons is a dependency-confusion proof-of-concept squatting the internal scope name @waves/icons. Its package.json declares a preinstall lifecycle hook that runs inline Node code (node -e...) which reads os.hostname() and os.userInfo().username and transmits them via http.get to a hardcoded beacon URL http://127.0.0.1:8099/?pkg=&host=&user=. The hook also prints a marker string '[BUGBOUNTY] @waves/icons dep confusion EXECUTED' to confirm execution. The code path runs automatically on npm install on any machine that resolves this squatted scope, collecting installer host identifiers and sending them to an attacker-chosen endpoint. Although the beacon is currently set to loopback (127.0.0.1), it is a hardcoded destination the publisher controls and can trivially be changed or paired with an active listener; the install-time execution, host reconnaissance, and unsolicited outbound HTTP are present as published.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020684",
            "import_time":  "2026-09-29T22:18:23.7952268Z",
            "modified_time":  "2026-09-29T22:11:59Z",
            "sha256":  "bdeb076eee35958fd0520e7f9cca9d361c47f02cb81c73288609ecdfb60bdbb1",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @rutxploit-sec/waves-icons

Package

Name
@rutxploit-sec/waves-icons
View open source insights on deps.dev
Purl
pkg:npm/%40rutxploit-sec/waves-icons

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "b79ace4e230f024668e150c29a718d56941cdccdfa7cb88e981315ee7272fda6",
            "tlsh":  "9b019ef44520e8176d8e016c066f650bf1e25b464865ec219adf380cc3b86b90e7b6a5"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "waves-icons-1.0.0.tgz",
            "hashes":  {
                "sha1":  "24d672ef1264fcce6411cf2e43d2d2876e51c581",
                "sha512_sri":  "sha512-TvAcEGknVKyde6DO5KwMgtc0ho5Be2Ese6cUYhzF/KrrH2WNsY1SVM4H1xdXea1BCfTeBpCDRPuCnSMlCfKvqw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-icons/MAL-2026-17291.json"