@galicia-toolkit-nestjs-20/archetype@999.0.2
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC
OSV ID
MAL-2026-17725
Ecosystem
npm
Summary
On module load, index.js unconditionally require()s a bundled native binary at prebuilds/<platform>-<arch>/metrics.node inside a try/catch that swallows errors. The ELF reads installer-side credential-grade environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, uid, cwd, and uname, and POSTs a JSON payload to the hardcoded host oob.s4yhii.com via a raw 'POST /native HTTP/1.0' request. The binary calls fork+setsid to detach from the host process. The exfiltration destination is embedded inside the compiled addon rather than exposed in JavaScript, placing it beyond source-level inspection. The declared package scope (NestJS archetype toolkit) has no relationship to the destination host or to native-code execution, and the package ships no C/C++ sources corresponding to the shipped.node binary.
Source: amazon-inspector (662603823964bdbc871f386498e949d768c84d99645690ee3b5e904b458536db)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.