@galicia-toolkit-nestjs-20-lite/commons@999.0.3
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 9:52 PM UTC
OSV ID
MAL-2026-17729
Ecosystem
npm
Summary
package.json declares a preinstall hook node index.js || true, which require()'s a bundled native addon at prebuilds/<platform>-<arch>/metrics.node. On N-API registration the addon reads AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, and AZURE_DEVOPS_EXT_PAT, collects hostname/user/cwd, and POSTs the data as JSON to http://oob.s4yhii.com/native. The payload is concealed inside a compiled.node binary named metrics (symbol do_report, cover-story env var _METRICS_PKG, JSON field src:native) with no corresponding C/C++ source shipped; the package otherwise advertises itself as a NestJS commons library, and shipping a native socket-opening module is inconsistent with that purpose. The implausibly high version 999.0.3 on a @...-lite/commons scope is consistent with a dependency-confusion lure targeting an internal package name.
Source: amazon-inspector (9974df3d2695630f5921c98037f0359ed3948cc0afd0c13d4ad5043819950f15)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.