-= Per source details. Do not edit below this line.=-
The package ships a tiny index.js that require()s a bundled ELF at prebuilds/linux-x64/metrics.node inside a swallow-all try/catch on module load. No C/C++ source, binding.gyp, or node-gyp/prebuild tooling is present, so the native binary cannot be rebuilt from source and its behavior is opaque to consumers. Strings extracted from the binary show it reads CI and cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, username and cwd, then opens a raw socket to the hardcoded host oob.s4yhii.com and issues POST /native HTTP/1.0 with a JSON body of the collected values. The addon daemonizes via fork+setsid to persist beyond the parent process. The destination host is unrelated to NestJS or any plausible publisher of a 'commons' utility. The package name mimics an internal-looking org scope and is published at version 999.0.6 with no repository and an UNLICENSED field, matching the dependency-confusion lure shape intended to win resolution against a private internal package of a similarly-named scope.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021302",
"import_time": "2026-10-09T13:46:18.294142771Z",
"modified_time": "2026-10-09T13:38:00Z",
"sha256": "37676e64576d3dc8fa07b541477894ba45dc0af760d06bb4630bb26f29be16f7",
"source": "amazon-inspector",
"versions": [
"999.0.7"
]
},
{
"id": "IN-MAL-2026-021329",
"import_time": "2026-10-09T13:46:20.353498672Z",
"modified_time": "2026-10-09T13:42:04Z",
"sha256": "6ac8bb5bf597abb810ef4fec7dd153b4c7403dc6fcaec9e6d1bb538aa6c6f396",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
},
{
"id": "IN-MAL-2026-021290",
"import_time": "2026-10-09T13:46:17.249958788Z",
"modified_time": "2026-10-09T13:36:09Z",
"sha256": "6b7cdcec1573755daec3eab422bec9fadf804064fb5c5ce97b908fed5e2ab831",
"source": "amazon-inspector",
"versions": [
"999.0.8"
]
},
{
"id": "IN-MAL-2026-021325",
"import_time": "2026-10-09T13:46:20.048867916Z",
"modified_time": "2026-10-09T13:41:28Z",
"sha256": "eae27acb3901d275439e482d51a1451df67c1a6b2011f35881253a3fa8d2456b",
"source": "amazon-inspector",
"versions": [
"999.0.6"
]
},
{
"id": "IN-MAL-2026-021338",
"import_time": "2026-10-09T17:16:16.835908736Z",
"modified_time": "2026-10-09T17:08:31Z",
"sha256": "e6473289d56c3d58e09f9c54a2a235341e884470a8b607c22ae8c078a744834a",
"source": "amazon-inspector",
"versions": [
"3.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "prebuilds/linux-x64/metrics.node",
"sha256": "daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375",
"tlsh": "8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a"
},
{
"path": "package.json",
"sha256": "c667734240f4a5cd8743a5a958ba9bf356027e6c870187e5b7f6eae8abcbd8dd",
"tlsh": "10c09b78d5315c2b1a415f5dadd52c5955ef066641cdc51842315330c2aaabc41cd16b"
}
],
"package_integrity": [
{
"filename": "commons-999.0.7.tgz",
"hashes": {
"sha1": "1b449670ceb97171ec50f92588771d885aa9f990",
"sha512_sri": "sha512-eFfOTDiNLN8HiHdrsv5AIRSejzLSSFilaVuXC+gaUpzlcVluMck/l1jy7hHStsBrY9EFYtvXvHxb5dDDh0UYfw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs/commons/MAL-2026-17722.json"