Logo
npm

@brick-v2/table@999.0.3

Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 2:49 PM UTC

Malicious

OSV ID

MAL-2026-17718

Ecosystem

npm

Summary

@brick-v2/table presents a trivial Angular-style logger/table shim (forRoot/createLogger/version no-ops) while index.js unconditionally side-loads prebuilds/<platform>-<arch>/metrics.node on require(). The native addon reads credential-shaped environment variables from the installer — AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN — along with hostname, uid, cwd, OS, arch, and release, and POSTs them as JSON over raw HTTP/1.0 to the hardcoded host oob.s4yhii.com at path /native. The native code calls fork+setsid to detach the exfil process so it survives after the host process exits. The destination is not first-party, is not caller-configurable, and the cover-story naming (package name unrelated to behavior, 'metrics.node' filename, _METRICS_PKG env var) disguises the stealer as telemetry. The version number 999.0.2 is implausibly high for the package name, consistent with a dependency-confusion lure.

Source: amazon-inspector (1fdd2bc5b913543c62603b366fb4e1261407f63541e4b01ff7e0052e522523e0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.