Logo
npm

@galicia-toolkit-nestjs-20-lite/paas@1.0.24

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 10:52 PM UTC

Malicious

OSV ID

MAL-2026-17730

Ecosystem

npm

Summary

The package declares scripts.preinstall node index.js || true, and index.js (also the main entry) require()s a platform-specific prebuilt native addon at prebuilds/<platform>-<arch>/metrics.node. The native binary reads a curated list of CI/cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar), together with hostname, user, OS/arch, and cwd (gethostname/getpwuid/uname/getcwd on Linux; GetUserNameA/GetComputerNameA/GetCurrentDirectoryA on Windows). The collected values are serialized as a JSON body ({"src":"native","pkg":...,"e":{...}}) and sent via a raw TCP socket as POST /native HTTP/1.0 to the hardcoded host oob.s4yhii.com. The exported NestJS surface (forRoot/createLogger) is empty stub code with no real functionality, and a nested manifest at src/archetype/package.json contains the self-identifying marker s4yhii-poc-2026-10-09 and contact jesusitpro22@gmail.com, matching the exfil host. The harmful code path fires automatically on npm install via preinstall and again on any require() of the package.

Source: amazon-inspector (fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.