@galicia-toolkit/spa-build-config@999.0.5
Malicious code in @galicia-toolkit/spa-build-config (npm)
Analysis
@galicia-toolkit/spa-build-config@999.0.5 is a dependency-confusion stub (sentinel version 999.0.5, no repository, no functional build-config code) that executes a payload from its postinstall hook ("node postinstall.js || true"). The hook, in postinstall.js, fingerprints the installing machine — hostname, platform, architecture, OS release, Node version, working directory, PID, uptime, memory, CPU model/count, the current username, home directory, and all non-internal network interfaces — and dumps the full list of process.env keys plus the values of CI/credential-adjacent variables including CI, BUILD_NUMBER, BUILD_ID, JENKINS_URL, JENKINS_HOME, GITHUB_ACTIONS, GITLAB_CI, SYSTEM_TEAMFOUNDATIONCOLLECTIONURI, CODEBUILD_BUILD_ID, npm_config_registry, npm_package_name, NODE_ENV, HOME, COMPUTERNAME, USERDOMAIN and PATH. The collected JSON is POSTed to hxxp://oob[.]s4yhii[.]com:9999/dep-confusion, with a DNS-tunnel fallback that hex-encodes the hostname, username and platform-arch into subdomains of h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com and m[.]dc[.]oob[.]s4yhii[.]com via dns.resolve. Any machine that installs this package leaks its build environment and CI metadata to the operator.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:26 PM
- analyzed
- Oct 8, 2026, 03:28 PM
Related advisories
- @galicia-toolkit/spa-build-config@999.0.6 same package
- @galicia-toolkit/spa-build-config@0.0.0-stage same package
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/tag-manager@0.0.0-stage
- @galicia-toolkit/core@0.0.0-stage
- css-reading-display-polyfill@1.0.0
- @worrisome/aaaa@1.0.0
- unreal-horde-dashboard@99999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.