LWA-2026-12701 MAL-2026-17690 ↗ confirmed malware

@galicia-toolkit/spa-build-config@999.0.5

Malicious code in @galicia-toolkit/spa-build-config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1016 · System Network Configuration DiscoveryT1552 · Unsecured CredentialsT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@galicia-toolkit/spa-build-config@999.0.5 is a dependency-confusion stub (sentinel version 999.0.5, no repository, no functional build-config code) that executes a payload from its postinstall hook ("node postinstall.js || true"). The hook, in postinstall.js, fingerprints the installing machine — hostname, platform, architecture, OS release, Node version, working directory, PID, uptime, memory, CPU model/count, the current username, home directory, and all non-internal network interfaces — and dumps the full list of process.env keys plus the values of CI/credential-adjacent variables including CI, BUILD_NUMBER, BUILD_ID, JENKINS_URL, JENKINS_HOME, GITHUB_ACTIONS, GITLAB_CI, SYSTEM_TEAMFOUNDATIONCOLLECTIONURI, CODEBUILD_BUILD_ID, npm_config_registry, npm_package_name, NODE_ENV, HOME, COMPUTERNAME, USERDOMAIN and PATH. The collected JSON is POSTed to hxxp://oob[.]s4yhii[.]com:9999/dep-confusion, with a DNS-tunnel fallback that hex-encodes the hostname, username and platform-arch into subdomains of h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com and m[.]dc[.]oob[.]s4yhii[.]com via dns.resolve. Any machine that installs this package leaks its build environment and CI metadata to the operator.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 03:26 PM
analyzed
Oct 8, 2026, 03:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.