LWA-2026-12755 confirmed malware

@galicia-toolkit-nestjs/archetype@999.0.1

Malicious code in @galicia-toolkit-nestjs/archetype (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

Dependency-confusion sentinel stub. The package publishes a sentinel version (999.0.1) on the scoped name @galicia-toolkit-nestjs/archetype so that it wins version resolution against any internal package of the same name, and ships a 263-byte index.js whose only logic is an out-of-band callback: five seconds after the module is required it reads the installer's hostname via os.hostname() and issues a DNS lookup for '<hostname>.a999[.]dc[.]oob[.]s4yhii[.]com', leaking the victim hostname to an attacker-controlled DNS server and confirming that the package was installed inside the target network. There is no install hook, no second-stage payload, and no credential, file, or environment-variable access — the beacon fires on require(). IOC: DNS callback domain a999[.]dc[.]oob[.]s4yhii[.]com (wildcard subdomain of s4yhii[.]com).

analyzed by
Leitwacht
first seen
Oct 9, 2026, 08:34 AM
analyzed
Oct 9, 2026, 08:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.