@rutxploit-sec/subsplash-google-tag-manager@1.0.0
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC
OSV ID
MAL-2026-17289
Ecosystem
npm
Summary
package.json declares a preinstall script that executes inline Node code reading os.hostname() and os.userInfo().username and issuing an HTTP GET to http://127.0.0.1:8099/ carrying those identifiers along with the impersonated package name. The package is published under @rutxploit-sec but its manifest description and index.js console output identify it as representing the private scope @subsplash/google-tag-manager, and any installer whose resolver picks this public name over the intended private package will execute the preinstall code and disclose hostname and username. The beacon destination in this artifact is loopback (127.0.0.1:8099), consistent with a proof-of-concept collector rather than a live external C2, but the install-time execution primitive and dependency-confusion targeting are the full attack shape.
Source: amazon-inspector (8fe2c746dc5c09bc67257fd4eba671824806c9080b7ca94949e45175deb03b8d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.