MAL-2026-17722

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs/commons/MAL-2026-17722.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17722
Published
2026-10-09T13:36:09Z
Modified
2026-10-09T17:30:03Z
Summary
Malicious code in @galicia-toolkit-nestjs/commons (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (eae27acb3901d275439e482d51a1451df67c1a6b2011f35881253a3fa8d2456b)

The package ships a tiny index.js that require()s a bundled ELF at prebuilds/linux-x64/metrics.node inside a swallow-all try/catch on module load. No C/C++ source, binding.gyp, or node-gyp/prebuild tooling is present, so the native binary cannot be rebuilt from source and its behavior is opaque to consumers. Strings extracted from the binary show it reads CI and cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, username and cwd, then opens a raw socket to the hardcoded host oob.s4yhii.com and issues POST /native HTTP/1.0 with a JSON body of the collected values. The addon daemonizes via fork+setsid to persist beyond the parent process. The destination host is unrelated to NestJS or any plausible publisher of a 'commons' utility. The package name mimics an internal-looking org scope and is published at version 999.0.6 with no repository and an UNLICENSED field, matching the dependency-confusion lure shape intended to win resolution against a private internal package of a similarly-named scope.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021302",
            "import_time": "2026-10-09T13:46:18.294142771Z",
            "modified_time": "2026-10-09T13:38:00Z",
            "sha256": "37676e64576d3dc8fa07b541477894ba45dc0af760d06bb4630bb26f29be16f7",
            "source": "amazon-inspector",
            "versions": [
                "999.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-021329",
            "import_time": "2026-10-09T13:46:20.353498672Z",
            "modified_time": "2026-10-09T13:42:04Z",
            "sha256": "6ac8bb5bf597abb810ef4fec7dd153b4c7403dc6fcaec9e6d1bb538aa6c6f396",
            "source": "amazon-inspector",
            "versions": [
                "999.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021290",
            "import_time": "2026-10-09T13:46:17.249958788Z",
            "modified_time": "2026-10-09T13:36:09Z",
            "sha256": "6b7cdcec1573755daec3eab422bec9fadf804064fb5c5ce97b908fed5e2ab831",
            "source": "amazon-inspector",
            "versions": [
                "999.0.8"
            ]
        },
        {
            "id": "IN-MAL-2026-021325",
            "import_time": "2026-10-09T13:46:20.048867916Z",
            "modified_time": "2026-10-09T13:41:28Z",
            "sha256": "eae27acb3901d275439e482d51a1451df67c1a6b2011f35881253a3fa8d2456b",
            "source": "amazon-inspector",
            "versions": [
                "999.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-021338",
            "import_time": "2026-10-09T17:16:16.835908736Z",
            "modified_time": "2026-10-09T17:08:31Z",
            "sha256": "e6473289d56c3d58e09f9c54a2a235341e884470a8b607c22ae8c078a744834a",
            "source": "amazon-inspector",
            "versions": [
                "3.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @galicia-toolkit-nestjs/commons

Package

Name
@galicia-toolkit-nestjs/commons
View open source insights on deps.dev
Purl
pkg:npm/%40galicia-toolkit-nestjs/commons

Affected ranges

Affected versions

3.*
3.0.1
999.*
999.0.1
999.0.6
999.0.7
999.0.8

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "prebuilds/linux-x64/metrics.node",
            "sha256": "daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375",
            "tlsh": "8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a"
        },
        {
            "path": "package.json",
            "sha256": "c667734240f4a5cd8743a5a958ba9bf356027e6c870187e5b7f6eae8abcbd8dd",
            "tlsh": "10c09b78d5315c2b1a415f5dadd52c5955ef066641cdc51842315330c2aaabc41cd16b"
        }
    ],
    "package_integrity": [
        {
            "filename": "commons-999.0.7.tgz",
            "hashes": {
                "sha1": "1b449670ceb97171ec50f92588771d885aa9f990",
                "sha512_sri": "sha512-eFfOTDiNLN8HiHdrsv5AIRSejzLSSFilaVuXC+gaUpzlcVluMck/l1jy7hHStsBrY9EFYtvXvHxb5dDDh0UYfw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs/commons/MAL-2026-17722.json"