@galicia-toolkit/spa-build-config@0.0.0-stage
Malicious code in @galicia-toolkit/spa-build-config (npm)
Analysis
@galicia-toolkit/spa-build-config@0.0.0-stage is an empty placeholder publish: the tarball contains only package.json (name, version "0.0.0-stage", "stub": true, description "Temporary package placeholder for staged publishing") and a README stating it is a temporary holding version awaiting a staged release. It ships no JavaScript, no lifecycle hooks, no bin entries and no dependencies, so this version carries no executable payload — this advisory is metadata-only and there are no network IOCs, dropped files, or credential access to report for it. The publish reserves the @galicia-toolkit/spa-build-config name, a name previously used to distribute malicious code; an inert stub holding that name is consistent with staging ahead of a later payload-bearing release, and installers should treat any future version of this package as untrusted.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:59 PM
- analyzed
- Oct 8, 2026, 03:59 PM
Related advisories
- @galicia-toolkit/spa-build-config@999.0.6 same package
- @galicia-toolkit/spa-build-config@999.0.5 same package
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/tag-manager@0.0.0-stage
- @galicia-toolkit/core@0.0.0-stage
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- dsh-h3@0.0.0-stage
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.