MAL-2026-17728

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/archetype/MAL-2026-17728.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17728
Published
2026-10-09T13:36:26Z
Modified
2026-10-09T14:00:07Z
Summary
Malicious code in @galicia-toolkit-nestjs-20-lite/archetype (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152)

On npm install, this package runs node index.js || true as a preinstall script. index.js loads a platform-specific native addon from prebuilds/<platform>-<arch>/metrics.node. The Linux and Windows binaries contain the hardcoded host oob.s4yhii.com and a POST /native HTTP/1.0 request line with a JSON template carrying src, pkg, h (hostname), u (username), os, arch, rel, cwd, and e (an environment-variable dictionary). The native code reads a hardcoded set of credential-bearing environment variables including AWS access keys, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, Azure DevOps PAT, and GitHub Actions runtime/ID tokens, and ships them to that host over a raw socket (getaddrinfo/connect/send; WS2_32 on Windows). The Linux variant uses fork+setsid to detach the exfiltration process from the install. The shipped JavaScript is a stub exporting empty forRoot/createLogger, with no real functionality beyond loading the addon. The package name uses a scoped namespace that resembles an internal toolkit and is published at version 999.0.3, a version-overshoot pattern consistent with dependency-confusion targeting private registries.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021333",
            "import_time": "2026-10-09T13:46:20.653804737Z",
            "modified_time": "2026-10-09T13:42:43Z",
            "sha256": "1d1a25f90c7a853514f2a5c1e87796552feb4f2fb49d9b5c45e48663460fb39e",
            "source": "amazon-inspector",
            "versions": [
                "999.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-021305",
            "import_time": "2026-10-09T13:46:18.517998654Z",
            "modified_time": "2026-10-09T13:38:30Z",
            "sha256": "ca2bb9e88ac3e21ede8e26df45e0611e198da1b4e8878e7ea5b34cea607c54f2",
            "source": "amazon-inspector",
            "versions": [
                "999.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-021314",
            "import_time": "2026-10-09T13:46:19.223528541Z",
            "modified_time": "2026-10-09T13:39:44Z",
            "sha256": "2bd0caaff4a987206b203555ef41da62e723aafc55ca767a9f0c1a0face68ec1",
            "source": "amazon-inspector",
            "versions": [
                "999.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021292",
            "import_time": "2026-10-09T13:46:17.434243358Z",
            "modified_time": "2026-10-09T13:36:26Z",
            "sha256": "524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152",
            "source": "amazon-inspector",
            "versions": [
                "999.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @galicia-toolkit-nestjs-20-lite/archetype

Package

Name
@galicia-toolkit-nestjs-20-lite/archetype
View open source insights on deps.dev
Purl
pkg:npm/%40galicia-toolkit-nestjs-20-lite/archetype

Affected ranges

Affected versions

999.*
999.0.1
999.0.2
999.0.3
999.0.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "cb-minimal.js",
            "sha256": "16e7b1448727da6e3a8ed3c5df27925bf481b6941a4934a9f297882b8ade58eb",
            "tlsh": "2df0acc0b2d0b1a132beb65498b6110213f2d4b674c37dd4599c84993bacaa200779ff"
        }
    ],
    "package_integrity": [
        {
            "filename": "archetype-999.0.5.tgz",
            "hashes": {
                "sha1": "9b376273df21352fa5f6674d89022c64c3e1de7f",
                "sha512_sri": "sha512-Y3D2D3IaTErXC1AoMb0SwJL24F5r6bbSaGm3RBgKRlAQmXbHZEEqFGq150pFAsrx+pNaPsJONriGDVyOV49uGQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/archetype/MAL-2026-17728.json"