LWA-2026-12699 MAL-2026-17691 ↗ confirmed malware

@galicia-toolkit/tag-manager@999.0.3

Malicious code in @galicia-toolkit/tag-manager (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@galicia-toolkit/tag-manager@999.0.3 is a dependency-confusion package: it ships a sentinel version (999.0.3) under a scope that mimics an internal corporate toolkit, and its postinstall hook (`node postinstall.js || true`) executes on every install. The hook performs host reconnaissance — hostname, working directory, platform, architecture, Node.js version, and the USER/USERNAME/LOGNAME environment variable — hex-encodes each value, and exfiltrates it over DNS by resolving it as a subdomain label under oob[.]s4yhii[.]com: `<hex-hostname>.<pkg-tag>.h[.]dc[.]oob[.]s4yhii[.]com`, `<hex-cwd>.<pkg-tag>.c[.]dc[.]oob[.]s4yhii[.]com`, `<platform-arch-node>.<pkg-tag>.m[.]dc[.]oob[.]s4yhii[.]com`, and `<hex-user>.<pkg-tag>.u[.]dc[.]oob[.]s4yhii[.]com`. The `|| true` suffix suppresses install errors so the beacon fails silently and the install appears to succeed. No credentials, tokens, or files are read; the payload is a DNS-based host-fingerprinting beacon that leaks the installer's host and user context to an attacker-controlled domain.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 03:19 PM
analyzed
Oct 8, 2026, 03:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.