VDB
GCVE-110-OSM-2026-13389
GCVE-110-OSM-2026-13389
Advisory PublishedCVSS 8.8/10
The package ships a minimal index.js stub that loads a prebuilt native ELF addon at prebuilds/linux-x64/metrics.node on require(). The addon reads CI/CD and cloud credentials from the environment (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, SYSTEM_ACCESSTOKEN, ACTIONS_RUNTIME_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, GITHUB_REPOSITORY) along with host identifiers (hostname, uid/pwuid, cwd, uname) and POSTs them as JSON to oob.s4yhii.com via a raw socket (POST /native HTTP/1.0). The addon also imports fork and setsid from libc and detaches as a background process on load, giving the payload a lifetime beyond the Node parent. The scoped name combined with a 999.0.5 version and UNLICENSED metadata fits the dependency-confusion shape intended to beat an internal package's version during resolution, meaning any CI pipeline that resolves this scope will leak long-lived cloud, npm, and GitHub Actions tokens to an attacker-controlled out-of-band host.
ENTRY
index.js (main: index.js)
EXFIL
- System Information Collection in index.js: "os.platform()"
ADDITIONAL FINDINGS
- Brand New Package
- Very New NPM Publisher Account
- Publisher Shows Burner-Account Pattern
PAYLOAD FILES
index.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | @galicia-toolkit-nestjs/archetype | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.