-= Per source details. Do not edit below this line.=-
@brick-v2/icons@999.0.3 is a dependency-confusion credential stealer. The package's package.json declares a preinstall script node index.js, and index.js's only behavior is to require a platform-specific prebuilt native addon from prebuilds/<platform>-<arch>/metrics.node. The native binary reads a curated list of CI and cloud secrets from the environment — AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar — along with hostname, username, cwd, and OS fields, and POSTs them as JSON to the hardcoded attacker endpoint oob.s4yhii.com at path /native. The JS shim presents a benign Angular-style facade (forRoot, createLogger, version exports) under a plausible scoped name, while the real behavior lives in the opaque native binary; no build system, binding.gyp, or source is shipped. The inflated version 999.0.3 is designed to win semver resolution against any legitimate internal @brick-v2/icons package, targeting private registries via dependency confusion. Harm is auto-executed on npm install via the preinstall hook, before any user code runs.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021308",
"import_time": "2026-10-09T13:46:18.762929577Z",
"modified_time": "2026-10-09T13:38:57Z",
"sha256": "88a6c17d632b5a7940e2ea85e756778a9f39e80f8e91402e4b46f556b6bea317",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
},
{
"id": "IN-MAL-2026-021283",
"import_time": "2026-10-09T13:46:16.61724421Z",
"modified_time": "2026-10-09T13:35:02Z",
"sha256": "915977ddb276c313e2977875d853dfba4eebd12f75ad0826008866b5059c68a8",
"source": "amazon-inspector",
"versions": [
"999.0.3"
]
},
{
"id": "IN-MAL-2026-021295",
"import_time": "2026-10-09T13:46:17.676638062Z",
"modified_time": "2026-10-09T13:36:55Z",
"sha256": "ee63e57c42a765834eecfcad6263ffcd4daf526bd263d6ed2bc8401e9b1d4db2",
"source": "amazon-inspector",
"versions": [
"999.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "prebuilds/linux-x64/metrics.node",
"sha256": "3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26",
"tlsh": "cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"
},
{
"path": "index.js",
"sha256": "437f6c81830bd7ac15efe3ef2928d92f59c450029b1bcc21d27db09504cd59c4",
"tlsh": "54f02ed53fa9b355a1777664d55b015668ffd4f0141db784c45cc4d026a198809738fc"
}
],
"package_integrity": [
{
"filename": "icons-999.0.1.tgz",
"hashes": {
"sha1": "adc9d1ea6c102925d891efa912db457f33e05df4",
"sha512_sri": "sha512-tBoBhCp6TomVJLfI6Xba0gn9uIKryqbTgD6InIZIbE59ttv5CS4JkQbIXCaiPyYsdf406o4eXqCPKSgRM4vKGw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/icons/MAL-2026-17717.json"