-= Per source details. Do not edit below this line.=-
The package's main entry index.js loads a prebuilt native binary at prebuilds/<platform>-<arch>/metrics.node inside a top-level try/catch, executing native code within the Node process as soon as the module is required. The ELF binary reads credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN, along with hostname, uid, and current working directory, and POSTs them as JSON to the hardcoded host oob.s4yhii.com via a raw socket (POST /native HTTP/1.0). The native code also invokes fork/setsid to detach from the parent process. The package is published as @brick-v2/core at version 999.0.1 with a trivial JS wrapper, a generic core module description, and UNLICENSED — a shape consistent with a dependency-confusion payload targeting a private @brick-v2 scope so that npm resolution prefers this public version over an internal package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021309",
"import_time": "2026-10-09T13:46:18.836800095Z",
"modified_time": "2026-10-09T13:39:05Z",
"sha256": "13cc187815f5f1b0024df22bab31f1735b2bb864854af665422a8401a7672226",
"source": "amazon-inspector",
"versions": [
"999.0.2"
]
},
{
"id": "IN-MAL-2026-021315",
"import_time": "2026-10-09T13:46:19.303415364Z",
"modified_time": "2026-10-09T13:39:53Z",
"sha256": "90c1fd9505ce4256620f9cb647e3a57a5af52539aa1e717a3eecb0485dec8c83",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "prebuilds/linux-x64/metrics.node",
"sha256": "daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375",
"tlsh": "8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a"
},
{
"path": "index.js",
"sha256": "28a4105532d31a66371b6137846227bf97a38d10f3c18833e3dabd535e6a5ee3",
"tlsh": "00f09ed97fa5b35a626676a8d66f015564ffc4f0042cbac4c448c9e127b09480e639fc"
}
],
"package_integrity": [
{
"filename": "core-999.0.2.tgz",
"hashes": {
"sha1": "d821df08e6706e25ae21685a64e310c86d29a051",
"sha512_sri": "sha512-LT2G7XVm0Gjx4js7K11mW0TLE/MS7y3qlPZMPRBhMrF02E0m/sl3r4o4mTVaDxxr/IRVUDtBG/0mbF8ZDMs8+Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/core/MAL-2026-17715.json"