Logo
npm

@galicia-toolkit-cheques-nc/front@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC

Malicious

OSV ID

MAL-2026-17720

Ecosystem

npm

Summary

Scoped npm package @galicia-toolkit-cheques-nc/front published at version 999.0.3 with UNLICENSED, no README, and no repository. package.json declares a preinstall hook node index.js || true, which loads a platform-specific prebuilt native addon at prebuilds/<platform>-<arch>/metrics.node. The shipped Linux ELF and Windows PE binaries contain hardcoded references to CI/CD credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, SYSTEM_ACCESSTOKEN) and POST their values together with host identifiers as JSON to the hardcoded non-publisher endpoint oob.s4yhii.com /native. The Linux binary additionally imports fork, setsid, socket, connect, and send, daemonizing a background process that maintains outbound contact to the same host; the Windows binary uses the equivalent WSAStartup/getaddrinfo/connect sequence. No native source, binding.gyp, or build script is shipped, so the opaque binary is not reproducible from the tarball. The scoped name and 999.0.3 version shape are consistent with a dependency-confusion attack targeting an internal corporate scope so that public resolution of this artifact triggers the preinstall exfiltration.

Source: amazon-inspector (29d819cdd288d1d18b8d76fbca2b2113941f344a5a80b2676ea5714367d8af44)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.