@galicia-toolkit/spa-build-config@999.0.6
Malicious code in @galicia-toolkit/spa-build-config (npm)
Analysis
@galicia-toolkit/spa-build-config@999.0.6 ships a postinstall hook (package.json: "postinstall": "node postinstall.js || true") that runs on every install and exfiltrates the installer's environment. postinstall.js collects host and CI metadata — hostname, platform, arch, OS release, Node version, cwd, pid, uptime, memory, CPU model, username, home directory, and all non-internal network interfaces — then reads a targeted list of credential-bearing environment variables: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_DEFAULT_REGION, GITHUB_TOKEN, GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_REF, GITHUB_SHA, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, ACTIONS_RUNTIME_TOKEN, plus Jenkins/GitLab/CodeBuild/Azure DevOps CI markers, and the full sorted list of process.env keys. The collected JSON is sent via HTTP POST to hxxp://oob[.]s4yhii[.]com:9999/dep-confusion, and three DNS beacons encode the hostname (hex), username (hex), and platform-arch as subdomains of h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com and m[.]dc[.]oob[.]s4yhii[.]com. All network errors are swallowed so the install completes silently. The package is a 3KB stub published at sentinel version 999.0.6 on a scoped name, consistent with a dependency-confusion attack against an internal scope; the payload steals live cloud, source-control and package-registry credentials from any machine or CI runner that installs it. IOCs: HTTP C2 oob[.]s4yhii[.]com:9999 (path /dep-confusion); DNS exfiltration domains h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com, m[.]dc[.]oob[.]s4yhii[.]com.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 04:20 PM
- analyzed
- Oct 8, 2026, 04:21 PM
Related advisories
- @galicia-toolkit/spa-build-config@0.0.0-stage same package
- @galicia-toolkit/spa-build-config@999.0.5 same package
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/tag-manager@0.0.0-stage
- @galicia-toolkit/core@0.0.0-stage
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- hardhat-deep@2.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.