@galicia-toolkit-nestjs/commons@999.0.8
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC
OSV ID
MAL-2026-17722
Ecosystem
npm
Summary
The package ships a tiny index.js that require()s a bundled ELF at prebuilds/linux-x64/metrics.node inside a swallow-all try/catch on module load. No C/C++ source, binding.gyp, or node-gyp/prebuild tooling is present, so the native binary cannot be rebuilt from source and its behavior is opaque to consumers. Strings extracted from the binary show it reads CI and cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, username and cwd, then opens a raw socket to the hardcoded host oob.s4yhii.com and issues POST /native HTTP/1.0 with a JSON body of the collected values. The addon daemonizes via fork+setsid to persist beyond the parent process. The destination host is unrelated to NestJS or any plausible publisher of a 'commons' utility. The package name mimics an internal-looking org scope and is published at version 999.0.6 with no repository and an UNLICENSED field, matching the dependency-confusion lure shape intended to win resolution against a private internal package of a similarly-named scope.
Source: amazon-inspector (eae27acb3901d275439e482d51a1451df67c1a6b2011f35881253a3fa8d2456b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.