@galicia-toolkit-nestjs/archetype@999.0.1
Malicious code in @galicia-toolkit-nestjs/archetype (npm)
Analysis
Dependency-confusion sentinel stub. The package publishes a sentinel version (999.0.1) on the scoped name @galicia-toolkit-nestjs/archetype so that it wins version resolution against any internal package of the same name, and ships a 263-byte index.js whose only logic is an out-of-band callback: five seconds after the module is required it reads the installer's hostname via os.hostname() and issues a DNS lookup for '<hostname>.a999[.]dc[.]oob[.]s4yhii[.]com', leaking the victim hostname to an attacker-controlled DNS server and confirming that the package was installed inside the target network. There is no install hook, no second-stage payload, and no credential, file, or environment-variable access — the beacon fires on require(). IOC: DNS callback domain a999[.]dc[.]oob[.]s4yhii[.]com (wildcard subdomain of s4yhii[.]com).
- analyzed by
- Leitwacht
- first seen
- Oct 9, 2026, 08:34 AM
- analyzed
- Oct 9, 2026, 08:35 AM
Related advisories
- @galicia-toolkit-nestjs/paas@999.0.3
- @galicia-toolkit-nestjs/commons@999.0.1
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/spa-build-config@999.0.5
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- @nf-addons/am-global-header@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.