Logo
npm

@brick-v2/tour@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC

Malicious

OSV ID

MAL-2026-17719

Ecosystem

npm

Summary

The package presents itself as an Angular-style module exposing forRoot/createLogger stubs and a version field, but these exports are no-ops. The real behavior is in a bundled prebuilt native addon at prebuilds/linux-x64/metrics.node and prebuilds/win32-x64/metrics.node. package.json declares "preinstall": "node index.js || true", and index.js loads the platform-specific metrics.node via require(path.join(__dirname,'prebuilds', os.platform()+'-'+os.arch(),'metrics.node')), so the native addon is executed automatically on npm install and again on require(). The native binary reads a broad set of credential-grade environment variables and host identifiers — AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, SYSTEM_ACCESSTOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, AZURE_DEVOPS_EXT_PAT, plus hostname, username, cwd, OS and arch — and POSTs them as JSON (template {"src":"native","pkg":"%s",...}) to oob.s4yhii.com at path /native over HTTP/1.0. The || true in the preinstall hook suppresses errors so the install appears to succeed silently. The Angular-shaped JS wrapper, the generic tour package name, and the metrics.node filename function as a cover story disguising a credential stealer.

Source: amazon-inspector (aabec40c085d56f59b4ca696eefe600f450a03284df0d77f562d861fed091bee)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.