LWA-2026-12702 confirmed malware

@galicia-toolkit/core@0.0.0-stage

Malicious code in @galicia-toolkit/core (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@galicia-toolkit/core@0.0.0-stage is a code-free placeholder publish: the tarball contains only package.json (153 bytes) and README.md (190 bytes) — no scripts, no bin entries, no dependencies, no lifecycle hooks and no executable files. The package claims the @galicia-toolkit scope, which impersonates the Galicia banking brand, and its README describes it as a "temporary holding version" awaiting a staged release. This is a name-reservation publish: the scope is being claimed so that a later version can ship a payload under a trusted-looking banking namespace. This version contains no malicious code and no network indicators — the risk is the reserved namespace and the follow-on release it stages. Consumers and the brand owner should treat any future version published under this scope as untrusted.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 03:58 PM
analyzed
Oct 8, 2026, 04:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.