{"id":"MAL-2026-17730","summary":"Malicious code in @galicia-toolkit-nestjs-20-lite/paas (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443)\nThe package declares scripts.preinstall `node index.js || true`, and index.js (also the main entry) require()s a platform-specific prebuilt native addon at prebuilds/\u003cplatform\u003e-\u003carch\u003e/metrics.node. The native binary reads a curated list of CI/cloud credential environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar), together with hostname, user, OS/arch, and cwd (gethostname/getpwuid/uname/getcwd on Linux; GetUserNameA/GetComputerNameA/GetCurrentDirectoryA on Windows). The collected values are serialized as a JSON body (`{\"src\":\"native\",\"pkg\":...,\"e\":{...}}`) and sent via a raw TCP socket as `POST /native HTTP/1.0` to the hardcoded host oob.s4yhii.com. The exported NestJS surface (forRoot/createLogger) is empty stub code with no real functionality, and a nested manifest at src/archetype/package.json contains the self-identifying marker `s4yhii-poc-2026-10-09` and contact `jesusitpro22@gmail.com`, matching the exfil host. The harmful code path fires automatically on `npm install` via preinstall and again on any require() of the package.\n","modified":"2026-10-09T14:00:07.106152545Z","published":"2026-10-09T13:37:13Z","database_specific":{"malicious-packages-origins":[{"sha256":"1f601ddafaebf7b8f8da9edca602c2508b0f31a6104f05652f5efe6dc3ac5fd1","source":"amazon-inspector","versions":["1.0.20"],"id":"IN-MAL-2026-021321","import_time":"2026-10-09T13:46:19.75198757Z","modified_time":"2026-10-09T13:40:50Z"},{"modified_time":"2026-10-09T13:42:32Z","sha256":"5637a8332816c563bcbd0638b0016ba4d3d6bab1b10241890b54928448617f60","source":"amazon-inspector","versions":["1.0.24"],"id":"IN-MAL-2026-021332","import_time":"2026-10-09T13:46:20.577243972Z"},{"sha256":"72c2df12f3a74cd97923e96848399730f8163c9bc614c95f809aa2fde6dc0f5f","source":"amazon-inspector","versions":["1.0.21"],"id":"IN-MAL-2026-021331","import_time":"2026-10-09T13:46:20.502901614Z","modified_time":"2026-10-09T13:42:24Z"},{"versions":["1.0.22"],"id":"IN-MAL-2026-021297","import_time":"2026-10-09T13:46:17.920435218Z","modified_time":"2026-10-09T13:37:13Z","sha256":"fb9736fcd5112c468c10509da5d624384a70802de5e20b218ad2cbebe0c7a443","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/paas/v/1.0.20"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/paas/v/1.0.24"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/paas/v/1.0.21"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@galicia-toolkit-nestjs-20-lite/paas/v/1.0.22"}],"affected":[{"package":{"name":"@galicia-toolkit-nestjs-20-lite/paas","ecosystem":"npm","purl":"pkg:npm/%40galicia-toolkit-nestjs-20-lite/paas"},"versions":["1.0.20","1.0.24","1.0.21","1.0.22"],"database_specific":{"indicators":{"evidence_files":[{"path":"prebuilds/linux-x64/metrics.node","sha256":"3f8833d49735dfdfe9bdef504bbb53ff069cb48a3953d9af08659d1c5560cf26","tlsh":"cf72775bb361ce3bc4dc4334055b5a70b1b29870e77353231b11a1bb3d927885ebae9a"},{"tlsh":"fed0a755c4506d1708d50b8c7a788d1155f789bf450aa49c034ba218958c9f7266839e","path":"src/archetype/package.json","sha256":"4c383950e430128de9b1721300b6c81dbb1de46de13640933576a6127481c6ce"}],"package_integrity":[{"filename":"paas-1.0.20.tgz","hashes":{"sha512_sri":"sha512-5dJVHVpNjinURr2LrKQ9ZRXVfL7ZumFVm6V5v4t0cetw0ZbSOUh++sx5tYI3KNrz/TiVa68P6mU/QsUWB7W2+A==","sha1":"f2bc3280f618fb66139e30f79664d063177d54d0"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@galicia-toolkit-nestjs-20-lite/paas/MAL-2026-17730.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}