Logo
npm

@brick-v2/brand@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 2:49 PM UTC

Malicious

OSV ID

MAL-2026-17714

Ecosystem

npm

Summary

package.json declares a preinstall hook node index.js || true that loads a prebuilt native addon at prebuilds/<platform>-<arch>/metrics.node. The addon reads credential-grade environment variables (AWS_SECRET_ACCESS_KEY and other AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT) and host identifiers (hostname via gethostname/GetComputerNameA, username via getpwuid/GetUserNameA, uname release, cwd, package name), serializes them into a JSON payload of shape {"src":"native","pkg":...,"h":...,"u":...,"os":...,"arch":...,"rel":...,"cwd":...,"e":{...}}, and transmits it via a raw TCP socket (socket/connect/send, with setsid+fork daemonization on Linux) to the hardcoded host oob.s4yhii.com using POST /native HTTP/1.0. The same exfiltration behavior is present in both the linux-x64 and win32-x64 prebuilt binaries. The JavaScript entry point exports only inert NestJS-style forRoot / createLogger placeholders; the entire operational behavior resides in the opaque native binary. The package is published under the private-looking scope @brick-v2 at version 999.0.3, a version-inflation shape consistent with dependency-confusion resolution against an internal @brick-v2 scope.

Source: amazon-inspector (a194395a620ef40055a22d7beccbab1e1ca0c662afe83b9ee2fb23d07ebaedc5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.