@galicia-toolkit/core@0.0.0-stage
Malicious code in @galicia-toolkit/core (npm)
Analysis
@galicia-toolkit/core@0.0.0-stage is a code-free placeholder publish: the tarball contains only package.json (153 bytes) and README.md (190 bytes) — no scripts, no bin entries, no dependencies, no lifecycle hooks and no executable files. The package claims the @galicia-toolkit scope, which impersonates the Galicia banking brand, and its README describes it as a "temporary holding version" awaiting a staged release. This is a name-reservation publish: the scope is being claimed so that a later version can ship a payload under a trusted-looking banking namespace. This version contains no malicious code and no network indicators — the risk is the reserved namespace and the follow-on release it stages. Consumers and the brand owner should treat any future version published under this scope as untrusted.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:58 PM
- analyzed
- Oct 8, 2026, 04:01 PM
Related advisories
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/tag-manager@0.0.0-stage
- @galicia-toolkit/error-master@0.0.0-stage
- @galicia-toolkit/spa-build-config@0.0.0-stage
- @galicia-toolkit/spa-build-config@999.0.5
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.