@galicia-toolkit/spa-build-config@999.0.6
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17690
Ecosystem
npm
Summary
The package's postinstall script runs automatically on npm install and collects installer-side host and credential data: hostname, username, network interfaces, the full list of process.env keys, and the values of credential-grade environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, and ACTIONS_RUNTIME_TOKEN. The collected JSON blob is POSTed to oob.s4yhii.com on port 9999 at path /dep-confusion, and hostname/username are additionally beaconed via DNS subdomain lookups under *.dc.oob.s4yhii.com. The package name shape and version (999.0.6) are consistent with a dependency-confusion lure targeting an internal scope. A self-declared 'bug bounty PoC' framing in package metadata does not change the behavior: these credentials grant AWS account access, GitHub repository write, npm publish rights, and GitHub Actions OIDC token exchange on the installing CI system.
Source: amazon-inspector (0d7fc29f59609ed2b5c7b54243b740e1daa001f3c76c4d1391edd85a528a4688)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.