OpenSSF/OSV advisory MAL-2026-17290 confirms this npm version as malicious. @rutxploit-sec/waves-button-poc@1.0.0 auto-executes host-identifier exfiltration on both `npm install` and `require`. package.json declares a preinstall script that runs `node -e` code which reads `os.hostname()` and `os.userInfo().username` and issues a plaintext HTTP GET to the hardcoded bare-IP endpoint http://80.225.217.8/poc/dep-confusion-proof.html, passing the package name, host, and user as query parameters...
This report applies to @rutxploit-sec/waves-button-poc@3.0.0.
2.0.0, 3.0.0
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.