{"id":"MAL-2026-17726","summary":"Malicious code in @galicia-toolkit-nestjs-20/commons (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5b719740efc4b3e93e85668e2e787b39a8d91e15abbe9c39f5d156e118745caa)\nOn require(), index.js loads a bundled ELF native addon at prebuilds/linux-x64/metrics.node inside a silent try/catch. The addon reads CI/cloud credential environment variables (AWS_SECRET_ACCESS_KEY and related AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_RUNTIME_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, user, and cwd, and POSTs them as JSON to the hardcoded non-first-party host oob.s4yhii.com at the path /native. The addon also calls fork and setsid to detach from the loader process after transmission, so the exfiltration continues in the background without blocking the caller. The package ships at version 999.0.1 under scope @galicia-toolkit-nestjs-20 with no library functionality beyond loading this addon — the inflated version, scope-mimicry, and payload-only contents are the canonical dependency-confusion shape. Packaging the exfiltration logic as a compiled.node binary rather than JavaScript, combined with the silent try/catch loader and the fork+setsid detach, is deliberate anti-analysis around the credential-theft primitive.\n","modified":"2026-10-09T14:00:06.270301067Z","published":"2026-10-09T13:35:40Z","database_specific":{"malicious-packages-origins":[{"versions":["999.0.2"],"id":"IN-MAL-2026-021306","import_time":"2026-10-09T13:46:18.593209714Z","modified_time":"2026-10-09T13:38:39Z","sha256":"418f9501530a35aa52b2c35b7ce12d757c8472763708baa60097f3e1a6d8d4e5","source":"amazon-inspector"},{"id":"IN-MAL-2026-021287","import_time":"2026-10-09T13:46:17.02929709Z","modified_time":"2026-10-09T13:35:40Z","sha256":"46e8c8fd81b9076dcfdfd0296e023046283d466f75c04e28bfd55e8ef1a6ea52","source":"amazon-inspector","versions":["999.0.3"]},{"id":"IN-MAL-2026-021319","import_time":"2026-10-09T13:46:19.607043104Z","modified_time":"2026-10-09T13:40:30Z","sha256":"5b719740efc4b3e93e85668e2e787b39a8d91e15abbe9c39f5d156e118745caa","source":"amazon-inspector","versions":["999.0.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20/commons/v/999.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20/commons/v/999.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20/commons/v/999.0.1"}],"affected":[{"package":{"name":"@galicia-toolkit-nestjs-20/commons","ecosystem":"npm","purl":"pkg:npm/%40galicia-toolkit-nestjs-20/commons"},"versions":["999.0.2","999.0.3","999.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"daedefd6a8a02449e29a163a1a92edc0859c0cdb814ec1024b6615fa78bdd375","tlsh":"8272641bb261ce3bc4dc4278015b5ab0b1b25474e77353231b10a1ba3e927485ebaf9a","path":"prebuilds/linux-x64/metrics.node"},{"path":"index.js","sha256":"919b188bf33f45001e024d6fa464021a80a3042e14c05433990efb800478fa5c","tlsh":"cdf00edcbfa9b31a62667568d66f0105a4fbc4f0042cbac4c009d6d127f0d880a638fc"}],"package_integrity":[{"filename":"commons-999.0.2.tgz","hashes":{"sha1":"e710400a212c84147e4965c666013fdc9b04dd95","sha512_sri":"sha512-STvVcsc0rn3JgX/Ot0QkJwx8X7wzn3I9FSfteGmp492Q4B9H7A5Tfj4M2zZ7DEczUziM2inoWeBKvGeqThfeVA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20/commons/MAL-2026-17726.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}