@galicia-toolkit-nestjs-20/commons@999.0.3
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 2:49 PM UTC
OSV ID
MAL-2026-17726
Ecosystem
npm
Summary
On require(), index.js loads a bundled ELF native addon at prebuilds/linux-x64/metrics.node inside a silent try/catch. The addon reads CI/cloud credential environment variables (AWS_SECRET_ACCESS_KEY and related AWS_*, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_RUNTIME_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN) along with hostname, user, and cwd, and POSTs them as JSON to the hardcoded non-first-party host oob.s4yhii.com at the path /native. The addon also calls fork and setsid to detach from the loader process after transmission, so the exfiltration continues in the background without blocking the caller. The package ships at version 999.0.1 under scope @galicia-toolkit-nestjs-20 with no library functionality beyond loading this addon — the inflated version, scope-mimicry, and payload-only contents are the canonical dependency-confusion shape. Packaging the exfiltration logic as a compiled.node binary rather than JavaScript, combined with the silent try/catch loader and the fork+setsid detach, is deliberate anti-analysis around the credential-theft primitive.
Source: amazon-inspector (5b719740efc4b3e93e85668e2e787b39a8d91e15abbe9c39f5d156e118745caa)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.