Logo
npm

@rutxploit-sec/waves-icons@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17291

Ecosystem

npm

Summary

@rutxploit-sec/waves-icons is a dependency-confusion proof-of-concept squatting the internal scope name @waves/icons. Its package.json declares a preinstall lifecycle hook that runs inline Node code (node -e...) which reads os.hostname() and os.userInfo().username and transmits them via http.get to a hardcoded beacon URL http://127.0.0.1:8099/?pkg=<pkg>&host=<host>&user=<user>. The hook also prints a marker string '[BUGBOUNTY] @waves/icons dep confusion EXECUTED' to confirm execution. The code path runs automatically on npm install on any machine that resolves this squatted scope, collecting installer host identifiers and sending them to an attacker-chosen endpoint. Although the beacon is currently set to loopback (127.0.0.1), it is a hardcoded destination the publisher controls and can trivially be changed or paired with an active listener; the install-time execution, host reconnaissance, and unsolicited outbound HTTP are present as published.

Source: amazon-inspector (bdeb076eee35958fd0520e7f9cca9d361c47f02cb81c73288609ecdfb60bdbb1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.