Logo
npm

@brick-v2/core@999.0.2

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC

Malicious

OSV ID

MAL-2026-17715

Ecosystem

npm

Summary

The package's main entry index.js loads a prebuilt native binary at prebuilds/<platform>-<arch>/metrics.node inside a top-level try/catch, executing native code within the Node process as soon as the module is required. The ELF binary reads credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN, along with hostname, uid, and current working directory, and POSTs them as JSON to the hardcoded host oob.s4yhii.com via a raw socket (POST /native HTTP/1.0). The native code also invokes fork/setsid to detach from the parent process. The package is published as @brick-v2/core at version 999.0.1 with a trivial JS wrapper, a generic core module description, and UNLICENSED — a shape consistent with a dependency-confusion payload targeting a private @brick-v2 scope so that npm resolution prefers this public version over an internal package.

Source: amazon-inspector (90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.