-= Per source details. Do not edit below this line.=-
The package declares scripts.preinstall node index.js || true, and index.js (also the main entry) require()s a platform-specific prebuilt native addon at prebuilds/-/metrics.node. The native binary reads a curated list of CI/cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar), together with hostname, user, OS/arch, and cwd (gethostname/getpwuid/uname/getcwd on Linux; GetUserNameA/GetComputerNameA/GetCurrentDirectoryA on Windows). The collected values are serialized as a JSON body ({"src":"native","pkg":...,"e":{...}}) and sent via a raw TCP socket as POST /native HTTP/1.0 to the hardcoded host oob.s4yhii.com. The exported NestJS surface (forRoot/createLogger) is empty stub code with no real functionality, and a nested manifest at src/archetype/package.json contains the self-identifying marker s4yhii-poc-2026-10-09 and contact jesusitpro22@gmail.com, matching the exfil host. The harmful code path fires automatically on npm install via preinstall and again on any require() of the package.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021321",
"import_time": "2026-10-09T13:46:19.75198757Z",
"modified_time": "2026-10-09T13:40:50Z",
"sha256": "1f601ddafaebf7b8f8da9edca602c2508b0f31a6104f05652f5efe6dc3ac5fd1",
"source": "amazon-inspector",
"versions": [
"1.0.20"
]
},
{
"id": "IN-MAL-2026-021332",
"import_time": "2026-10-09T13:46:20.577243972Z",
"modified_time": "2026-10-09T13:42:32Z",
"sha256": "5637a8332816c563bcbd0638b0016ba4d3d6bab1b10241890b54928448617f60",
"source": "amazon-inspector",
"versions": [
"1.0.24"
]
},
{
"id": "IN-MAL-2026-021331",
"import_time": "2026-10-09T13:46:20.502901614Z",
"modified_time": "2026-10-09T13:42:24Z",
"sha256": "72c2df12f3a74cd97923e96848399730f8163c9bc614c95f809aa2fde6dc0f5f",
"source": "amazon-inspector",
"versions": [
"1.0.21"
]
},
{
"id": "IN-MAL-2026-021297",
"import_time": "2026-10-09T13:46:17.920435218Z",
"modified_time": "2026-10-09T13:37:13Z",
"sha256": "fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443",
"source": "amazon-inspector",
"versions": [
"1.0.22"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "prebuilds/linux-x64/metrics.node",
"sha256": "3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26",
"tlsh": "cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"
},
{
"path": "src/archetype/package.json",
"sha256": "4c383950e430128de9b1721300b6c81dbb1de46de13640933576a6127481c6ce",
"tlsh": "fed0a755c4506d1708d50b8c7a788d1155f789bf450aa49c034ba218958c9f7266839e"
}
],
"package_integrity": [
{
"filename": "paas-1.0.20.tgz",
"hashes": {
"sha1": "f2bc3280f618fb66139e30f79664d063177d54d0",
"sha512_sri": "sha512-5dJVHVpNjinURr2LrKQ9ZRXVfL7ZumFVm6V5v4t0cetw0ZbSOUh++sx5tYI3KNrz/TiVa68P6mU/QsUWB7W2+A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/paas/MAL-2026-17730.json"