@galicia-toolkit/tag-manager@999.0.6
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17691
Ecosystem
npm
Summary
@galicia-toolkit/tag-manager@999.0.6 is a scoped dependency-confusion squat whose entire payload runs from a postinstall hook. On npm install, postinstall.js reads a curated list of credential-grade environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, ACTIONS_ID_TOKEN_REQUEST_TOKEN), enumerates the full process.env key list, and collects host reconnaissance (hostname, username, platform, arch, kernel, cwd, uid, external IPs, CPU/memory). The collected data is exfiltrated over two channels to a hardcoded external host: an HTTP POST to oob.s4yhii.com:9999/dep-confusion, and DNS beacons encoding hostname/username under *.dc.oob.s4yhii.com. index.js is empty — the package has no library functionality; its only effect is the install-time exfiltration. The package.json uses an inflated 999.0.6 version consistent with winning resolution against an internal @galicia-toolkit scope. A self-label as a bug-bounty PoC in the description does not change the behavior: any installer that resolves this scoped name has its cloud and CI credentials sent to a non-first-party host.
Source: amazon-inspector (5e2accc91beaa067ef442b5dbedf2fb823cea321757875bff9f4cad10532c093)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.