{"id":"MAL-2026-17714","summary":"Malicious code in @brick-v2/brand (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5)\npackage.json declares a preinstall hook `node index.js || true` that loads a prebuilt native addon at prebuilds/\u003cplatform\u003e-\u003carch\u003e/metrics.node. The addon reads credential-grade environment variables (AWS_SECRET_ACCESS_KEY and other AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT) and host identifiers (hostname via gethostname/GetComputerNameA, username via getpwuid/GetUserNameA, uname release, cwd, package name), serializes them into a JSON payload of shape `{\"src\":\"native\",\"pkg\":...,\"h\":...,\"u\":...,\"os\":...,\"arch\":...,\"rel\":...,\"cwd\":...,\"e\":{...}}`, and transmits it via a raw TCP socket (socket/connect/send, with setsid+fork daemonization on Linux) to the hardcoded host oob.s4yhii.com using `POST /native HTTP/1.0`. The same exfiltration behavior is present in both the linux-x64 and win32-x64 prebuilt binaries. The JavaScript entry point exports only inert NestJS-style `forRoot` / `createLogger` placeholders; the entire operational behavior resides in the opaque native binary. The package is published under the private-looking scope `@brick-v2` at version `999.0.3`, a version-inflation shape consistent with dependency-confusion resolution against an internal `@brick-v2` scope.\n","modified":"2026-10-09T14:00:06.256777077Z","published":"2026-10-09T13:35:10Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-021313","import_time":"2026-10-09T13:46:19.147946933Z","modified_time":"2026-10-09T13:39:36Z","sha256":"197d8de60092ac86ecda23eedf003121f46b8a7c34c5f60eeabd6c23134e2983","source":"amazon-inspector","versions":["999.0.1"]},{"modified_time":"2026-10-09T13:35:10Z","sha256":"a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5","source":"amazon-inspector","versions":["999.0.3"],"id":"IN-MAL-2026-021284","import_time":"2026-10-09T13:46:16.693711029Z"},{"id":"IN-MAL-2026-021300","import_time":"2026-10-09T13:46:18.147710836Z","modified_time":"2026-10-09T13:37:42Z","sha256":"f7cfeebad59fc63be0a47be28ded37bfe722bbb39be81bb9d0fe9ba60f9db644","source":"amazon-inspector","versions":["999.0.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@brick-v2/brand/v/999.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@brick-v2/brand/v/999.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@brick-v2/brand/v/999.0.2"}],"affected":[{"package":{"name":"@brick-v2/brand","ecosystem":"npm","purl":"pkg:npm/%40brick-v2/brand"},"versions":["999.0.1","999.0.3","999.0.2"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26","tlsh":"cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a","path":"prebuilds/linux-x64/metrics.node"},{"sha256":"1a17d809f782d801d813f4a551fe60866bb8ac09855e8df71a7dc8b38ac3b19d","tlsh":"58c080705531142314c6dbe58ce249074adb0c6f004574041757552441fd73314ff33c","path":"package.json"}],"package_integrity":[{"filename":"brand-999.0.1.tgz","hashes":{"sha512_sri":"sha512-s/ZulG7hGTvmqtUG7BoFvovsjk6EykZAGUsYgqz6Im+yuEeMUxPBdzlRJWZtFilpWKGXl9G9F3xhuFjMMGXHxw==","sha1":"2a94637ece2a2f7905fea6375b9cb8ccb8c3cd20"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@brick-v2/brand/MAL-2026-17714.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}