@galicia-toolkit/tag-manager@0.0.0-stage
Malicious code in @galicia-toolkit/tag-manager (npm)
Analysis
@galicia-toolkit/tag-manager@0.0.0-stage is an inert placeholder publish: the tarball contains only a package.json ({"stub":true,"description":"Temporary package placeholder for staged publishing"}) and a README stating it is a temporary holding version awaiting a staged release. There is no executable code, no lifecycle hook, no dependency, and no network activity in this version, so installing it runs nothing. It is a name-reservation/staging artifact for a package name whose earlier version shipped malicious code; the placeholder reserves the name and version slot ahead of a payload release. No IOCs (no C2 host, URL, IP, dropped file, or credential path) are present in this version — the analysis of this artifact is metadata-only, and the concrete payload artifacts belong to the package family's other versions.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 03:59 PM
- analyzed
- Oct 8, 2026, 04:04 PM
Related advisories
- @galicia-toolkit/tag-manager@999.0.6 same package
- @galicia-toolkit/tag-manager@999.0.5 same package
- @galicia-toolkit/tag-manager@999.0.3 same package
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/core@0.0.0-stage
- @galicia-toolkit/error-master@0.0.0-stage
- @galicia-toolkit/spa-build-config@0.0.0-stage
- @galicia-toolkit/spa-build-config@999.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.