-= Per source details. Do not edit below this line.=-
On npm install, this package runs node index.js || true as a preinstall script. index.js loads a platform-specific native addon from prebuilds/<platform>-<arch>/metrics.node. The Linux and Windows binaries contain the hardcoded host oob.s4yhii.com and a POST /native HTTP/1.0 request line with a JSON template carrying src, pkg, h (hostname), u (username), os, arch, rel, cwd, and e (an environment-variable dictionary). The native code reads a hardcoded set of credential-bearing environment variables including AWS access keys, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, Azure DevOps PAT, and GitHub Actions runtime/ID tokens, and ships them to that host over a raw socket (getaddrinfo/connect/send; WS2_32 on Windows). The Linux variant uses fork+setsid to detach the exfiltration process from the install. The shipped JavaScript is a stub exporting empty forRoot/createLogger, with no real functionality beyond loading the addon. The package name uses a scoped namespace that resembles an internal toolkit and is published at version 999.0.3, a version-overshoot pattern consistent with dependency-confusion targeting private registries.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021333",
"import_time": "2026-10-09T13:46:20.653804737Z",
"modified_time": "2026-10-09T13:42:43Z",
"sha256": "1d1a25f90c7a853514f2a5c1e87796552feb4f2fb49d9b5c45e48663460fb39e",
"source": "amazon-inspector",
"versions": [
"999.0.5"
]
},
{
"id": "IN-MAL-2026-021305",
"import_time": "2026-10-09T13:46:18.517998654Z",
"modified_time": "2026-10-09T13:38:30Z",
"sha256": "ca2bb9e88ac3e21ede8e26df45e0611e198da1b4e8878e7ea5b34cea607c54f2",
"source": "amazon-inspector",
"versions": [
"999.0.2"
]
},
{
"id": "IN-MAL-2026-021314",
"import_time": "2026-10-09T13:46:19.223528541Z",
"modified_time": "2026-10-09T13:39:44Z",
"sha256": "2bd0caaff4a987206b203555ef41da62e723aafc55ca767a9f0c1a0face68ec1",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
},
{
"id": "IN-MAL-2026-021292",
"import_time": "2026-10-09T13:46:17.434243358Z",
"modified_time": "2026-10-09T13:36:26Z",
"sha256": "524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152",
"source": "amazon-inspector",
"versions": [
"999.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "cb-minimal.js",
"sha256": "16e7b1448727da6e3a8ed3c5df27925bf481b6941a4934a9f297882b8ade58eb",
"tlsh": "2df0acc0b2d0b1a132beb65498b6110213f2d4b674c37dd4599c84993bacaa200779ff"
}
],
"package_integrity": [
{
"filename": "archetype-999.0.5.tgz",
"hashes": {
"sha1": "9b376273df21352fa5f6674d89022c64c3e1de7f",
"sha512_sri": "sha512-Y3D2D3IaTErXC1AoMb0SwJL24F5r6bbSaGm3RBgKRlAQmXbHZEEqFGq150pFAsrx+pNaPsJONriGDVyOV49uGQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/archetype/MAL-2026-17728.json"