@galicia-toolkit-nestjs/paas@999.0.3
Malicious code in @galicia-toolkit-nestjs/paas (npm)
Analysis
@galicia-toolkit-nestjs/paas@999.0.3 is a sentinel-version stub (version 999.0.3 on a scoped name, 694-byte tarball, no repository) whose entire payload is a covert out-of-band callback. package/index.js exports inert NestJS shim stubs (forRoot/createLogger no-ops) and then, five seconds after the module is loaded, reads the installer's hostname with os.hostname() and issues a DNS resolution for "<hostname>.p999[.]dc[.]oob[.]s4yhii[.]com" inside a try/catch. Encoding the victim hostname as a DNS label under an attacker-controlled out-of-band interaction domain confirms the package was installed on the host and leaks the hostname to the operator; the DNS query is the exfiltration channel. No credentials, environment variables, wallet keys, or files are read, and there is no install hook — the beacon fires on require. IOC: DNS domain p999[.]dc[.]oob[.]s4yhii[.]com (base domain s4yhii[.]com).
- analyzed by
- Leitwacht
- first seen
- Oct 9, 2026, 08:51 AM
- analyzed
- Oct 9, 2026, 08:51 AM
Related advisories
- @galicia-toolkit-nestjs/archetype@999.0.1
- @galicia-toolkit-nestjs/commons@999.0.1
- @galicia-toolkit/spa-build-config@999.0.6
- @galicia-toolkit/tag-manager@999.0.6
- @galicia-toolkit/spa-build-config@999.0.5
- @galicia-toolkit/tag-manager@999.0.5
- @galicia-toolkit/tag-manager@999.0.3
- @nf-addons/am-global-header@9.9.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.