MAL-2026-17730

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/paas/MAL-2026-17730.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17730
Published
2026-10-09T13:37:13Z
Modified
2026-10-09T14:00:07Z
Summary
Malicious code in @galicia-toolkit-nestjs-20-lite/paas (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443)

The package declares scripts.preinstall node index.js || true, and index.js (also the main entry) require()s a platform-specific prebuilt native addon at prebuilds/-/metrics.node. The native binary reads a curated list of CI/cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar), together with hostname, user, OS/arch, and cwd (gethostname/getpwuid/uname/getcwd on Linux; GetUserNameA/GetComputerNameA/GetCurrentDirectoryA on Windows). The collected values are serialized as a JSON body ({"src":"native","pkg":...,"e":{...}}) and sent via a raw TCP socket as POST /native HTTP/1.0 to the hardcoded host oob.s4yhii.com. The exported NestJS surface (forRoot/createLogger) is empty stub code with no real functionality, and a nested manifest at src/archetype/package.json contains the self-identifying marker s4yhii-poc-2026-10-09 and contact jesusitpro22@gmail.com, matching the exfil host. The harmful code path fires automatically on npm install via preinstall and again on any require() of the package.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021321",
            "import_time": "2026-10-09T13:46:19.75198757Z",
            "modified_time": "2026-10-09T13:40:50Z",
            "sha256": "1f601ddafaebf7b8f8da9edca602c2508b0f31a6104f05652f5efe6dc3ac5fd1",
            "source": "amazon-inspector",
            "versions": [
                "1.0.20"
            ]
        },
        {
            "id": "IN-MAL-2026-021332",
            "import_time": "2026-10-09T13:46:20.577243972Z",
            "modified_time": "2026-10-09T13:42:32Z",
            "sha256": "5637a8332816c563bcbd0638b0016ba4d3d6bab1b10241890b54928448617f60",
            "source": "amazon-inspector",
            "versions": [
                "1.0.24"
            ]
        },
        {
            "id": "IN-MAL-2026-021331",
            "import_time": "2026-10-09T13:46:20.502901614Z",
            "modified_time": "2026-10-09T13:42:24Z",
            "sha256": "72c2df12f3a74cd97923e96848399730f8163c9bc614c95f809aa2fde6dc0f5f",
            "source": "amazon-inspector",
            "versions": [
                "1.0.21"
            ]
        },
        {
            "id": "IN-MAL-2026-021297",
            "import_time": "2026-10-09T13:46:17.920435218Z",
            "modified_time": "2026-10-09T13:37:13Z",
            "sha256": "fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443",
            "source": "amazon-inspector",
            "versions": [
                "1.0.22"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @galicia-toolkit-nestjs-20-lite/paas

Package

Name
@galicia-toolkit-nestjs-20-lite/paas
View open source insights on deps.dev
Purl
pkg:npm/%40galicia-toolkit-nestjs-20-lite/paas

Affected ranges

Affected versions

1.*
1.0.20
1.0.21
1.0.22
1.0.24

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "prebuilds/linux-x64/metrics.node",
            "sha256": "3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26",
            "tlsh": "cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"
        },
        {
            "path": "src/archetype/package.json",
            "sha256": "4c383950e430128de9b1721300b6c81dbb1de46de13640933576a6127481c6ce",
            "tlsh": "fed0a755c4506d1708d50b8c7a788d1155f789bf450aa49c034ba218958c9f7266839e"
        }
    ],
    "package_integrity": [
        {
            "filename": "paas-1.0.20.tgz",
            "hashes": {
                "sha1": "f2bc3280f618fb66139e30f79664d063177d54d0",
                "sha512_sri": "sha512-5dJVHVpNjinURr2LrKQ9ZRXVfL7ZumFVm6V5v4t0cetw0ZbSOUh++sx5tYI3KNrz/TiVa68P6mU/QsUWB7W2+A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/paas/MAL-2026-17730.json"