Logo
npm

@brick-v2/form@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC

Malicious

OSV ID

MAL-2026-17716

Ecosystem

npm

Summary

The package ships a tiny JavaScript stub at index.js that silently require()s a compiled native addon at prebuilds/linux-x64/metrics.node inside a try/catch that suppresses errors. On load, the addon reads a hardcoded list of credential-bearing environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS session token, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, SYSTEM_ACCESSTOKEN) along with hostname, user, cwd, and OS/arch, and sends them as a JSON body via a raw TCP socket (gethostbyname/socket/connect/send) in a 'POST /native HTTP/1.0' request to the hardcoded external host oob.s4yhii.com. The addon also imports fork and setsid, consistent with detaching into a background process so the exfiltration channel survives beyond the host Node process. The compiled ELF is the entire payload; the JS wrapper exposes no form-related functionality matching the stated 'form module' description. The package manifest (scoped name @brick-v2/form, inflated version 999.0.1, UNLICENSED, minimal metadata) matches the dependency-confusion shape used to outrank an internal private-registry package of the same scope.

Source: amazon-inspector (61727d51587469176de52cbc3c82a53b4572ecfc6c7f7b4c7edf534950b0f536)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.