LWA-2026-12704 MAL-2026-17690 ↗ confirmed malware

@galicia-toolkit/spa-build-config@0.0.0-stage

Malicious code in @galicia-toolkit/spa-build-config (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

@galicia-toolkit/spa-build-config@0.0.0-stage is an empty placeholder publish: the tarball contains only package.json (name, version "0.0.0-stage", "stub": true, description "Temporary package placeholder for staged publishing") and a README stating it is a temporary holding version awaiting a staged release. It ships no JavaScript, no lifecycle hooks, no bin entries and no dependencies, so this version carries no executable payload — this advisory is metadata-only and there are no network IOCs, dropped files, or credential access to report for it. The publish reserves the @galicia-toolkit/spa-build-config name, a name previously used to distribute malicious code; an inert stub holding that name is consistent with staging ahead of a later payload-bearing release, and installers should treat any future version of this package as untrusted.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 03:59 PM
analyzed
Oct 8, 2026, 03:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.