Logo
npm

@rutxploit-sec/subsplash-canny@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17288

Ecosystem

npm

Summary

npm package @rutxploit-sec/subsplash-canny declares a preinstall lifecycle script that runs node -e inline code reading os.hostname() and os.userInfo().username and issuing an HTTP GET to http://127.0.0.1:8099/ with those values as query parameters, plus a package identifier. The package.json description and README self-describe the artifact as a dependency-confusion proof-of-concept impersonating the private scoped name @subsplash/canny. Installing this package on any machine automatically executes the beacon at install time and transmits the installer's hostname and OS username to the configured endpoint. The current destination is loopback (127.0.0.1:8099), which limits real-world reach in this specific tarball, but the mechanism — arbitrary code execution and identity collection on npm install — is fully wired and would function identically against any remote endpoint.

Source: amazon-inspector (dc1ebadea2eb63a0fc7cf7446e36a589c5b87fc7d28e68b68145b98577107ebb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.