MAL-2026-17715

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/core/MAL-2026-17715.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17715
Published
2026-10-09T13:39:05Z
Modified
2026-10-09T14:00:07Z
Summary
Malicious code in @brick-v2/core (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83)

The package's main entry index.js loads a prebuilt native binary at prebuilds/<platform>-<arch>/metrics.node inside a top-level try/catch, executing native code within the Node process as soon as the module is required. The ELF binary reads credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN, along with hostname, uid, and current working directory, and POSTs them as JSON to the hardcoded host oob.s4yhii.com via a raw socket (POST /native HTTP/1.0). The native code also invokes fork/setsid to detach from the parent process. The package is published as @brick-v2/core at version 999.0.1 with a trivial JS wrapper, a generic core module description, and UNLICENSED — a shape consistent with a dependency-confusion payload targeting a private @brick-v2 scope so that npm resolution prefers this public version over an internal package.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021309",
            "import_time": "2026-10-09T13:46:18.836800095Z",
            "modified_time": "2026-10-09T13:39:05Z",
            "sha256": "13cc187815f5f1b0024df22bab31f1735b2bb864854af665422a8401a7672226",
            "source": "amazon-inspector",
            "versions": [
                "999.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-021315",
            "import_time": "2026-10-09T13:46:19.303415364Z",
            "modified_time": "2026-10-09T13:39:53Z",
            "sha256": "90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83",
            "source": "amazon-inspector",
            "versions": [
                "999.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @brick-v2/core

Package

Name
@brick-v2/core
View open source insights on deps.dev
Purl
pkg:npm/%40brick-v2/core

Affected ranges

Affected versions

999.*
999.0.1
999.0.2

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "prebuilds/linux-x64/metrics.node",
            "sha256": "daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375",
            "tlsh": "8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a"
        },
        {
            "path": "index.js",
            "sha256": "28a4105532d31a66371b6137846227bf97a38d10f3c18833e3dabd535e6a5ee3",
            "tlsh": "00f09ed97fa5b35a626676a8d66f015564ffc4f0042cbac4c448c9e127b09480e639fc"
        }
    ],
    "package_integrity": [
        {
            "filename": "core-999.0.2.tgz",
            "hashes": {
                "sha1": "d821df08e6706e25ae21685a64e310c86d29a051",
                "sha512_sri": "sha512-LT2G7XVm0Gjx4js7K11mW0TLE/MS7y3qlPZMPRBhMrF02E0m/sl3r4o4mTVaDxxr/IRVUDtBG/0mbF8ZDMs8+Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/core/MAL-2026-17715.json"