@galicia-toolkit/error-master@999.0.3
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:45 PM UTC
OSV ID
MAL-2026-17689
Ecosystem
npm
Summary
On npm install, this package's postinstall script (node postinstall.js) hex-encodes the installer's hostname, current working directory, platform/arch/Node version, and USER/USERNAME/LOGNAME values, and emits DNS queries whose subdomains encode that data under the hardcoded author-controlled zone oob.s4yhii.com, using an authoritative resolver as an out-of-band exfiltration channel. The package name and the version number 999.0.3 are consistent with a dependency-confusion payload shape designed to win resolution against an internal @galicia-toolkit/error-master package. The DNS-tunnel beacon fires automatically at install time with no installer action beyond npm install, leaking host and user identifiers to the attacker's authoritative nameserver.
Source: amazon-inspector (64345fa1c5c24196376e1a0cc8c14b6dcf3898e972b0b6fc23ae8f19d67b6f11)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.