@galicia-toolkit/tag-manager@999.0.3
Malicious code in @galicia-toolkit/tag-manager (npm)
Analysis
@galicia-toolkit/tag-manager@999.0.3 is a dependency-confusion package: it ships a sentinel version (999.0.3) under a scope that mimics an internal corporate toolkit, and its postinstall hook (`node postinstall.js || true`) executes on every install. The hook performs host reconnaissance — hostname, working directory, platform, architecture, Node.js version, and the USER/USERNAME/LOGNAME environment variable — hex-encodes each value, and exfiltrates it over DNS by resolving it as a subdomain label under oob[.]s4yhii[.]com: `<hex-hostname>.<pkg-tag>.h[.]dc[.]oob[.]s4yhii[.]com`, `<hex-cwd>.<pkg-tag>.c[.]dc[.]oob[.]s4yhii[.]com`, `<platform-arch-node>.<pkg-tag>.m[.]dc[.]oob[.]s4yhii[.]com`, and `<hex-user>.<pkg-tag>.u[.]dc[.]oob[.]s4yhii[.]com`. The `|| true` suffix suppresses install errors so the beacon fails silently and the install appears to succeed. No credentials, tokens, or files are read; the payload is a DNS-based host-fingerprinting beacon that leaks the installer's host and user context to an attacker-controlled domain.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:19 PM
- analyzed
- Oct 8, 2026, 03:20 PM
Related advisories
- @galicia-toolkit/tag-manager@999.0.6 same package
- @galicia-toolkit/tag-manager@0.0.0-stage same package
- @galicia-toolkit/tag-manager@999.0.5 same package
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/core@0.0.0-stage
- @galicia-toolkit/error-master@0.0.0-stage
- hardhat-deep@2.0.1
- css-reading-display-polyfill@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.