BUGBOUNTY PoC — proves preinstall executes on npm install (Subsplash dep-confusion via @waves/button)
An automatic preinstall hook transmits host-identifying information to an external IP address. Importing the package main module repeats the transmission.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the machine hostname and local account name to an external IP address during npm installation.
package.jsonView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.json#scripts.preinstallView on unpkgThe main module also collects and sends the hostname and account name when it is imported.
index.jsView on unpkg · L1This report applies to @rutxploit-sec/waves-button-poc@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the machine hostname and local account name to an external IP address during npm installation.
package.jsonView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.json#scripts.preinstallView on unpkgThe main module also collects and sends the hostname and account name when it is imported.
index.jsView on unpkg · L1