LWA-2026-12709 MAL-2026-17690 ↗ confirmed malware

@galicia-toolkit/spa-build-config@999.0.6

Malicious code in @galicia-toolkit/spa-build-config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1016 · System Network Configuration DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@galicia-toolkit/spa-build-config@999.0.6 ships a postinstall hook (package.json: "postinstall": "node postinstall.js || true") that runs on every install and exfiltrates the installer's environment. postinstall.js collects host and CI metadata — hostname, platform, arch, OS release, Node version, cwd, pid, uptime, memory, CPU model, username, home directory, and all non-internal network interfaces — then reads a targeted list of credential-bearing environment variables: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AWS_DEFAULT_REGION, GITHUB_TOKEN, GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_REF, GITHUB_SHA, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, ACTIONS_RUNTIME_TOKEN, plus Jenkins/GitLab/CodeBuild/Azure DevOps CI markers, and the full sorted list of process.env keys. The collected JSON is sent via HTTP POST to hxxp://oob[.]s4yhii[.]com:9999/dep-confusion, and three DNS beacons encode the hostname (hex), username (hex), and platform-arch as subdomains of h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com and m[.]dc[.]oob[.]s4yhii[.]com. All network errors are swallowed so the install completes silently. The package is a 3KB stub published at sentinel version 999.0.6 on a scoped name, consistent with a dependency-confusion attack against an internal scope; the payload steals live cloud, source-control and package-registry credentials from any machine or CI runner that installs it. IOCs: HTTP C2 oob[.]s4yhii[.]com:9999 (path /dep-confusion); DNS exfiltration domains h[.]dc[.]oob[.]s4yhii[.]com, u[.]dc[.]oob[.]s4yhii[.]com, m[.]dc[.]oob[.]s4yhii[.]com.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 04:20 PM
analyzed
Oct 8, 2026, 04:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.