{"id":"MAL-2026-17289","summary":"Malicious code in @rutxploit-sec/subsplash-google-tag-manager (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8fe2c746dc5c09bc67257fd4eba671824806c9080b7ca94949e45175deb03b8d)\npackage.json declares a preinstall script that executes inline Node code reading os.hostname() and os.userInfo().username and issuing an HTTP GET to http://127.0.0.1:8099/ carrying those identifiers along with the impersonated package name. The package is published under @rutxploit-sec but its manifest description and index.js console output identify it as representing the private scope @subsplash/google-tag-manager, and any installer whose resolver picks this public name over the intended private package will execute the preinstall code and disclose hostname and username. The beacon destination in this artifact is loopback (127.0.0.1:8099), consistent with a proof-of-concept collector rather than a live external C2, but the install-time execution primitive and dependency-confusion targeting are the full attack shape.\n","modified":"2026-09-29T22:31:17.089483642Z","published":"2026-09-29T22:11:49Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020683","import_time":"2026-09-29T22:18:23.760750178Z","modified_time":"2026-09-29T22:11:49Z","sha256":"8fe2c746dc5c09bc67257fd4eba671824806c9080b7ca94949e45175deb03b8d","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@rutxploit-sec/subsplash-google-tag-manager/v/1.0.0"}],"affected":[{"package":{"name":"@rutxploit-sec/subsplash-google-tag-manager","ecosystem":"npm","purl":"pkg:npm/%40rutxploit-sec/subsplash-google-tag-manager"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"426cb2c3e09d6eb5493e46cfa09013b295446eca60506227aa44b98df64b864c","tlsh":"e70190f6d318f4375ece0175663a101bb2f78f4784a06c70abee181c87963f61526ad2","path":"package.json"}],"package_integrity":[{"filename":"subsplash-google-tag-manager-1.0.0.tgz","hashes":{"sha1":"3638dd8c85fea6215d5ee33b0f1e53ce187aaa4d","sha512_sri":"sha512-nx94YmFAYVfYVDku/AfaFEA8RkVYEk8Y6eIZ0duI5GfWtl93Ern7pPtmlAZ4nuVB4KaCqxWFEksKQLNli8fBrg=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/subsplash-google-tag-manager/MAL-2026-17289.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}