-= Per source details. Do not edit below this line.=-
package.json declares a preinstall hook node index.js || true that loads a prebuilt native addon at prebuilds/-/metrics.node. The addon reads credential-grade environment variables (AWS_SECRET_ACCESS_KEY and other AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT) and host identifiers (hostname via gethostname/GetComputerNameA, username via getpwuid/GetUserNameA, uname release, cwd, package name), serializes them into a JSON payload of shape {"src":"native","pkg":...,"h":...,"u":...,"os":...,"arch":...,"rel":...,"cwd":...,"e":{...}}, and transmits it via a raw TCP socket (socket/connect/send, with setsid+fork daemonization on Linux) to the hardcoded host oob.s4yhii.com using POST /native HTTP/1.0. The same exfiltration behavior is present in both the linux-x64 and win32-x64 prebuilt binaries. The JavaScript entry point exports only inert NestJS-style forRoot / createLogger placeholders; the entire operational behavior resides in the opaque native binary. The package is published under the private-looking scope @brick-v2 at version 999.0.3, a version-inflation shape consistent with dependency-confusion resolution against an internal @brick-v2 scope.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021313",
"import_time": "2026-10-09T13:46:19.147946933Z",
"modified_time": "2026-10-09T13:39:36Z",
"sha256": "197d8de60092ac86ecda23eedf003121f46b8a7c34c5f60eeabd6c23134e2983",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
},
{
"id": "IN-MAL-2026-021284",
"import_time": "2026-10-09T13:46:16.693711029Z",
"modified_time": "2026-10-09T13:35:10Z",
"sha256": "a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5",
"source": "amazon-inspector",
"versions": [
"999.0.3"
]
},
{
"id": "IN-MAL-2026-021300",
"import_time": "2026-10-09T13:46:18.147710836Z",
"modified_time": "2026-10-09T13:37:42Z",
"sha256": "f7cfeebad59fc63be0a47be28ded37bfe722bbb39be81bb9d0fe9ba60f9db644",
"source": "amazon-inspector",
"versions": [
"999.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "prebuilds/linux-x64/metrics.node",
"sha256": "3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26",
"tlsh": "cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"
},
{
"path": "package.json",
"sha256": "1a17d809f782d801d813f4a551fe60866bb8ac09855e8df71a7dc8b38ac3b19d",
"tlsh": "58c080705531142314c6dbe58ce249074adb0c6f004574041757552441fd73314ff33c"
}
],
"package_integrity": [
{
"filename": "brand-999.0.1.tgz",
"hashes": {
"sha1": "2a94637ece2a2f7905fea6375b9cb8ccb8c3cd20",
"sha512_sri": "sha512-s/ZulG7hGTvmqtUG7BoFvovsjk6EykZAGUsYgqz6Im+yuEeMUxPBdzlRJWZtFilpWKGXl9G9F3xhuFjMMGXHxw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/brand/MAL-2026-17714.json"