@galicia-toolkit/error-master@0.0.0-stage
Malicious code in @galicia-toolkit/error-master (npm)
Analysis
@galicia-toolkit/error-master@0.0.0-stage ships no executable code: the tarball contains only a package.json (161 bytes) and a README.md (190 bytes), with no scripts, no bin entries, no dependencies, and no JavaScript files. The manifest sets "stub": true and describes itself as a "Temporary package placeholder for staged publishing"; the README calls it a "Temporary Holding Version" awaiting a staged release. The package reserves a scoped name under a non-standard version tag (0.0.0-stage) with no repository or license field and no functional content. This is a name-reservation/staging publish — the shape used to claim a scoped package name ahead of shipping a payload in a later version. No malicious code is present in this version and there are no network indicators; the assessment is metadata-only.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:59 PM
- analyzed
- Oct 8, 2026, 03:59 PM
Related advisories
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/tag-manager@0.0.0-stage
- @galicia-toolkit/spa-build-config@0.0.0-stage
- @galicia-toolkit/spa-build-config@999.0.5
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- dsh-h3@0.0.0-stage
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.