{"id":"MAL-2026-17288","summary":"Malicious code in @rutxploit-sec/subsplash-canny (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dc1ebadea2eb63a0fc7cf7446e36a589c5b87fc7d28e68b68145b98577107ebb)\nnpm package @rutxploit-sec/subsplash-canny declares a preinstall lifecycle script that runs `node -e` inline code reading `os.hostname()` and `os.userInfo().username` and issuing an HTTP GET to http://127.0.0.1:8099/ with those values as query parameters, plus a package identifier. The package.json description and README self-describe the artifact as a dependency-confusion proof-of-concept impersonating the private scoped name `@subsplash/canny`. Installing this package on any machine automatically executes the beacon at install time and transmits the installer's hostname and OS username to the configured endpoint. The current destination is loopback (127.0.0.1:8099), which limits real-world reach in this specific tarball, but the mechanism — arbitrary code execution and identity collection on `npm install` — is fully wired and would function identically against any remote endpoint.\n","modified":"2026-09-29T22:31:17.085137456Z","published":"2026-09-29T22:11:37Z","database_specific":{"malicious-packages-origins":[{"sha256":"dc1ebadea2eb63a0fc7cf7446e36a589c5b87fc7d28e68b68145b98577107ebb","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020682","import_time":"2026-09-29T22:18:23.735732683Z","modified_time":"2026-09-29T22:11:37Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@rutxploit-sec/subsplash-canny/v/1.0.0"}],"affected":[{"package":{"name":"@rutxploit-sec/subsplash-canny","ecosystem":"npm","purl":"pkg:npm/%40rutxploit-sec/subsplash-canny"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-canny/MAL-2026-17288.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"subsplash-canny-1.0.0.tgz","hashes":{"sha1":"c30332e7583a93f4dcca05c4417e1d2ceb691744","sha512_sri":"sha512-6ONC8bP3VyFJd1iMjClObWjNbtiUK+V4MOE9M/h2xJ/0XBNo1tXObNl+qw4LwidrK5aRMrvtCOgsxybtuUB89w=="}}],"evidence_files":[{"path":"package.json","sha256":"1bc3cc6512e18fd7deb4ccead1597906e632252503785934cb3c60e03816afe0","tlsh":"f701f4f44110f4529d8d01b86a3f105bf5f1ef4681602c049ede140ccbd43f6096ea92"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}