Logo
npm

@brick-v2/icons@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 2:49 PM UTC

Malicious

OSV ID

MAL-2026-17717

Ecosystem

npm

Summary

@brick-v2/icons@999.0.3 is a dependency-confusion credential stealer. The package's package.json declares a preinstall script node index.js, and index.js's only behavior is to require a platform-specific prebuilt native addon from prebuilds/<platform>-<arch>/metrics.node. The native binary reads a curated list of CI and cloud secrets from the environment — AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, AZURE_DEVOPS_EXT_PAT, and similar — along with hostname, username, cwd, and OS fields, and POSTs them as JSON to the hardcoded attacker endpoint oob.s4yhii.com at path /native. The JS shim presents a benign Angular-style facade (forRoot, createLogger, version exports) under a plausible scoped name, while the real behavior lives in the opaque native binary; no build system, binding.gyp, or source is shipped. The inflated version 999.0.3 is designed to win semver resolution against any legitimate internal @brick-v2/icons package, targeting private registries via dependency confusion. Harm is auto-executed on npm install via the preinstall hook, before any user code runs.

Source: amazon-inspector (915977ddb276c313e2977875d853dfba4eebd12f75ad0826008866b5059c68a8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.