{"id":"MAL-2026-17291","summary":"Malicious code in @rutxploit-sec/waves-icons (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bdeb076eee35958fd0520e7f9cca9d361c47f02cb81c73288609ecdfb60bdbb1)\n@rutxploit-sec/waves-icons is a dependency-confusion proof-of-concept squatting the internal scope name @waves/icons. Its package.json declares a preinstall lifecycle hook that runs inline Node code (node -e...) which reads os.hostname() and os.userInfo().username and transmits them via http.get to a hardcoded beacon URL http://127.0.0.1:8099/?pkg=\u003cpkg\u003e&host=\u003chost\u003e&user=\u003cuser\u003e. The hook also prints a marker string '[BUGBOUNTY] @waves/icons dep confusion EXECUTED' to confirm execution. The code path runs automatically on npm install on any machine that resolves this squatted scope, collecting installer host identifiers and sending them to an attacker-chosen endpoint. Although the beacon is currently set to loopback (127.0.0.1), it is a hardcoded destination the publisher controls and can trivially be changed or paired with an active listener; the install-time execution, host reconnaissance, and unsolicited outbound HTTP are present as published.\n","modified":"2026-09-29T22:31:17.094604419Z","published":"2026-09-29T22:11:59Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-29T22:18:23.7952268Z","modified_time":"2026-09-29T22:11:59Z","sha256":"bdeb076eee35958fd0520e7f9cca9d361c47f02cb81c73288609ecdfb60bdbb1","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020684"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@rutxploit-sec/waves-icons/v/1.0.0"}],"affected":[{"package":{"name":"@rutxploit-sec/waves-icons","ecosystem":"npm","purl":"pkg:npm/%40rutxploit-sec/waves-icons"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"b79ace4e230f024668e150c29a718d56941cdccdfa7cb88e981315ee7272fda6","tlsh":"9b019ef44520e8176d8e016c066f650bf1e25b464865ec219adf380cc3b86b90e7b6a5"}],"package_integrity":[{"hashes":{"sha1":"24d672ef1264fcce6411cf2e43d2d2876e51c581","sha512_sri":"sha512-TvAcEGknVKyde6DO5KwMgtc0ho5Be2Ese6cUYhzF/KrrH2WNsY1SVM4H1xdXea1BCfTeBpCDRPuCnSMlCfKvqw=="},"filename":"waves-icons-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@rutxploit-sec/waves-icons/MAL-2026-17291.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}