Logo
npm

@galicia-toolkit-nestjs/archetype@999.0.6

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC

Malicious

OSV ID

MAL-2026-17721

Ecosystem

npm

Summary

The package ships a minimal index.js stub that loads a prebuilt native ELF addon at prebuilds/linux-x64/metrics.node on require(). The addon reads CI/CD and cloud credentials from the environment (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, GITHUB_REPOSITORY) along with host identifiers (hostname, uid/pwuid, cwd, uname) and POSTs them as JSON to oob.s4yhii.com via a raw socket (POST /native HTTP/1.0). The addon also imports fork and setsid from libc and detaches as a background process on load, giving the payload a lifetime beyond the Node parent. The scoped name combined with a 999.0.5 version and UNLICENSED metadata fits the dependency-confusion shape intended to beat an internal package's version during resolution, meaning any CI pipeline that resolves this scope will leak long-lived cloud, npm, and GitHub Actions tokens to an attacker-controlled out-of-band host.

Source: amazon-inspector (63cdc34da85584342e27bc84d22c01a826c71020b7bf07987626cbe457e2e560)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.