Logo
npm

@galicia-toolkit-nestjs-20-lite/archetype@999.0.5

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 10:52 PM UTC

Malicious

OSV ID

MAL-2026-17728

Ecosystem

npm

Summary

On npm install, this package runs node index.js || true as a preinstall script. index.js loads a platform-specific native addon from prebuilds/<platform>-<arch>/metrics.node. The Linux and Windows binaries contain the hardcoded host oob.s4yhii.com and a POST /native HTTP/1.0 request line with a JSON template carrying src, pkg, h (hostname), u (username), os, arch, rel, cwd, and e (an environment-variable dictionary). The native code reads a hardcoded set of credential-bearing environment variables including AWS access keys, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, Azure DevOps PAT, and GitHub Actions runtime/ID tokens, and ships them to that host over a raw socket (getaddrinfo/connect/send; WS2_32 on Windows). The Linux variant uses fork+setsid to detach the exfiltration process from the install. The shipped JavaScript is a stub exporting empty forRoot/createLogger, with no real functionality beyond loading the addon. The package name uses a scoped namespace that resembles an internal toolkit and is published at version 999.0.3, a version-overshoot pattern consistent with dependency-confusion targeting private registries.

Source: amazon-inspector (524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.