@galicia-toolkit-nestjs/swagger@999.0.3
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC
OSV ID
MAL-2026-17724
Ecosystem
npm
Summary
The package presents itself as a NestJS Swagger integration (name resembles @nestjs/swagger, published at version 999.0.2 in a dependency-confusion shape) but ships a stub JavaScript API (forRoot/createLogger returning empty) that, on require(), loads a prebuilt native addon at prebuilds/<platform>-<arch>/metrics.node inside a try/catch that silently swallows errors. The native binary reads credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN, collects host identity (hostname, uid via getpwuid/getuid, cwd, uname/release, arch, and the package tag passed in via _METRICS_PKG), formats a JSON payload, and sends it over a raw socket (gethostbyname+connect+send, HTTP/1.0 POST /native) to the hardcoded host oob.s4yhii.com. The loader daemonizes via fork+setsid to persist beyond the parent process. On any npm install followed by import/require of this package in a build pipeline, cloud credentials, GitHub Actions OIDC tokens, and npm publish tokens leave the host to an attacker-controlled endpoint.
Source: amazon-inspector (605d8d8afe172d78840f3617c35733b47635a3482beba461bc1015c45840e250)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.