MAL-2026-17714

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/brand/MAL-2026-17714.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17714
Published
2026-10-09T13:35:10Z
Modified
2026-10-09T14:00:06Z
Summary
Malicious code in @brick-v2/brand (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5)

package.json declares a preinstall hook node index.js || true that loads a prebuilt native addon at prebuilds/-/metrics.node. The addon reads credential-grade environment variables (AWS_SECRET_ACCESS_KEY and other AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT) and host identifiers (hostname via gethostname/GetComputerNameA, username via getpwuid/GetUserNameA, uname release, cwd, package name), serializes them into a JSON payload of shape {"src":"native","pkg":...,"h":...,"u":...,"os":...,"arch":...,"rel":...,"cwd":...,"e":{...}}, and transmits it via a raw TCP socket (socket/connect/send, with setsid+fork daemonization on Linux) to the hardcoded host oob.s4yhii.com using POST /native HTTP/1.0. The same exfiltration behavior is present in both the linux-x64 and win32-x64 prebuilt binaries. The JavaScript entry point exports only inert NestJS-style forRoot / createLogger placeholders; the entire operational behavior resides in the opaque native binary. The package is published under the private-looking scope @brick-v2 at version 999.0.3, a version-inflation shape consistent with dependency-confusion resolution against an internal @brick-v2 scope.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021313",
            "import_time": "2026-10-09T13:46:19.147946933Z",
            "modified_time": "2026-10-09T13:39:36Z",
            "sha256": "197d8de60092ac86ecda23eedf003121f46b8a7c34c5f60eeabd6c23134e2983",
            "source": "amazon-inspector",
            "versions": [
                "999.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021284",
            "import_time": "2026-10-09T13:46:16.693711029Z",
            "modified_time": "2026-10-09T13:35:10Z",
            "sha256": "a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5",
            "source": "amazon-inspector",
            "versions": [
                "999.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-021300",
            "import_time": "2026-10-09T13:46:18.147710836Z",
            "modified_time": "2026-10-09T13:37:42Z",
            "sha256": "f7cfeebad59fc63be0a47be28ded37bfe722bbb39be81bb9d0fe9ba60f9db644",
            "source": "amazon-inspector",
            "versions": [
                "999.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @brick-v2/brand

Package

Name
@brick-v2/brand
View open source insights on deps.dev
Purl
pkg:npm/%40brick-v2/brand

Affected ranges

Affected versions

999.*
999.0.1
999.0.2
999.0.3

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "prebuilds/linux-x64/metrics.node",
            "sha256": "3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26",
            "tlsh": "cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"
        },
        {
            "path": "package.json",
            "sha256": "1a17d809f782d801d813f4a551fe60866bb8ac09855e8df71a7dc8b38ac3b19d",
            "tlsh": "58c080705531142314c6dbe58ce249074adb0c6f004574041757552441fd73314ff33c"
        }
    ],
    "package_integrity": [
        {
            "filename": "brand-999.0.1.tgz",
            "hashes": {
                "sha1": "2a94637ece2a2f7905fea6375b9cb8ccb8c3cd20",
                "sha512_sri": "sha512-s/ZulG7hGTvmqtUG7BoFvovsjk6EykZAGUsYgqz6Im+yuEeMUxPBdzlRJWZtFilpWKGXl9G9F3xhuFjMMGXHxw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/brand/MAL-2026-17714.json"