{"id":"MAL-2026-17728","summary":"Malicious code in @galicia-toolkit-nestjs-20-lite/archetype (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152)\nOn `npm install`, this package runs `node index.js || true` as a `preinstall` script. `index.js` loads a platform-specific native addon from `prebuilds/\u003cplatform\u003e-\u003carch\u003e/metrics.node`. The Linux and Windows binaries contain the hardcoded host `oob.s4yhii.com` and a `POST /native HTTP/1.0` request line with a JSON template carrying `src`, `pkg`, `h` (hostname), `u` (username), `os`, `arch`, `rel`, `cwd`, and `e` (an environment-variable dictionary). The native code reads a hardcoded set of credential-bearing environment variables including AWS access keys, `GITHUB_TOKEN`, `NPM_TOKEN`, `NODE_AUTH_TOKEN`, Azure DevOps PAT, and GitHub Actions runtime/ID tokens, and ships them to that host over a raw socket (getaddrinfo/connect/send; WS2_32 on Windows). The Linux variant uses fork+setsid to detach the exfiltration process from the install. The shipped JavaScript is a stub exporting empty `forRoot`/`createLogger`, with no real functionality beyond loading the addon. The package name uses a scoped namespace that resembles an internal toolkit and is published at version 999.0.3, a version-overshoot pattern consistent with dependency-confusion targeting private registries.\n","modified":"2026-10-09T14:00:07.113606296Z","published":"2026-10-09T13:36:26Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-09T13:42:43Z","sha256":"1d1a25f90c7a853514f2a5c1e87796552feb4f2fb49d9b5c45e48663460fb39e","source":"amazon-inspector","versions":["999.0.5"],"id":"IN-MAL-2026-021333","import_time":"2026-10-09T13:46:20.653804737Z"},{"import_time":"2026-10-09T13:46:18.517998654Z","modified_time":"2026-10-09T13:38:30Z","sha256":"ca2bb9e88ac3e21ede8e26df45e0611e198da1b4e8878e7ea5b34cea607c54f2","source":"amazon-inspector","versions":["999.0.2"],"id":"IN-MAL-2026-021305"},{"sha256":"2bd0caaff4a987206b203555ef41da62e723aafc55ca767a9f0c1a0face68ec1","source":"amazon-inspector","versions":["999.0.1"],"id":"IN-MAL-2026-021314","import_time":"2026-10-09T13:46:19.223528541Z","modified_time":"2026-10-09T13:39:44Z"},{"source":"amazon-inspector","versions":["999.0.3"],"id":"IN-MAL-2026-021292","import_time":"2026-10-09T13:46:17.434243358Z","modified_time":"2026-10-09T13:36:26Z","sha256":"524c80bfea6a1b22cb0a4784d2763ccf83099faab3816c9fcb1ce39bb8813152"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/archetype/v/999.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/archetype/v/999.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/archetype/v/999.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/archetype/v/999.0.3"}],"affected":[{"package":{"name":"@galicia-toolkit-nestjs-20-lite/archetype","ecosystem":"npm","purl":"pkg:npm/%40galicia-toolkit-nestjs-20-lite/archetype"},"versions":["999.0.5","999.0.2","999.0.1","999.0.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"16e7b1448727da6e3a8ed3c5df27925bf481b6941a4934a9f297882b8ade58eb","tlsh":"2df0acc0b2d0b1a132beb65498b6110213f2d4b674c37dd4599c84993bacaa200779ff","path":"cb-minimal.js"}],"package_integrity":[{"filename":"archetype-999.0.5.tgz","hashes":{"sha1":"9b376273df21352fa5f6674d89022c64c3e1de7f","sha512_sri":"sha512-Y3D2D3IaTErXC1AoMb0SwJL24F5r6bbSaGm3RBgKRlAQmXbHZEEqFGq150pFAsrx+pNaPsJONriGDVyOV49uGQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/archetype/MAL-2026-17728.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}