LWA-2026-12756 confirmed malware

@galicia-toolkit-nestjs/paas@999.0.3

Malicious code in @galicia-toolkit-nestjs/paas (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

@galicia-toolkit-nestjs/paas@999.0.3 is a sentinel-version stub (version 999.0.3 on a scoped name, 694-byte tarball, no repository) whose entire payload is a covert out-of-band callback. package/index.js exports inert NestJS shim stubs (forRoot/createLogger no-ops) and then, five seconds after the module is loaded, reads the installer's hostname with os.hostname() and issues a DNS resolution for "<hostname>.p999[.]dc[.]oob[.]s4yhii[.]com" inside a try/catch. Encoding the victim hostname as a DNS label under an attacker-controlled out-of-band interaction domain confirms the package was installed on the host and leaks the hostname to the operator; the DNS query is the exfiltration channel. No credentials, environment variables, wallet keys, or files are read, and there is no install hook — the beacon fires on require. IOC: DNS domain p999[.]dc[.]oob[.]s4yhii[.]com (base domain s4yhii[.]com).

analyzed by
Leitwacht
first seen
Oct 9, 2026, 08:51 AM
analyzed
Oct 9, 2026, 08:51 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.