Logo
npm

@rutxploit-sec/waves-button-poc@3.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17290

Ecosystem

npm

Summary

@rutxploit-sec/waves-button-poc@1.0.0 auto-executes host-identifier exfiltration on both npm install and require. package.json declares a preinstall script that runs node -e code which reads os.hostname() and os.userInfo().username and issues a plaintext HTTP GET to the hardcoded bare-IP endpoint http://80.225.217.8/poc/dep-confusion-proof.html, passing the package name, host, and user as query parameters. The declared main entry index.js repeats the same behavior at module top level, so any consumer that requires the package also beacons the same identifiers to the same IP. The scoped name and PoC framing are consistent with a dependency-confusion proof-of-concept, but the shipped code performs unauthenticated identifier collection from every installer regardless of intent, and the destination is an attacker-chosen bare IP over cleartext HTTP.

Source: amazon-inspector (435937e521ca52ff4d99fd276136aff40364c4a88a3a4677cecf390c9d9bb600)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.