Malicious code in @galicia-toolkit/tag-manager (npm)
Description
The npm package @galicia-toolkit/tag-manager versions 999.0.3, 999.0.5, and 999.0.6 is a malicious dependency-confusion squat that executes code during installation to exfiltrate sensitive environment variables and host information to an external attacker-controlled server. It collects credential-grade environment variables such as AWS and GitHub tokens, enumerates system details, and sends this data via HTTP and DNS channels. The package contains no legitimate functionality and is designed solely for credential theft. Any system with this package installed should be considered fully compromised, and all secrets must be rotated immediately.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
@galicia-toolkit/tag-manager is a malicious npm package that abuses a postinstall hook to steal sensitive environment variables including AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, GITHUB_TOKEN, NPM_TOKEN, NODE_AUTH_TOKEN, and ACTIONS_ID_TOKEN_REQUEST_TOKEN. It also collects detailed host reconnaissance data such as hostname, username, platform, architecture, kernel version, current working directory, user ID, external IP addresses, and CPU/memory information. This data is exfiltrated to a hardcoded external host via HTTP POST requests and DNS beaconing. The package versioning is artificially inflated (999.0.x) to win dependency resolution conflicts within the @galicia-toolkit scope. The package has no legitimate code in its main index.js and is solely intended for credential theft during installation. Despite a self-label as a bug bounty proof-of-concept, the behavior is malicious and compromises any system that installs it.
Potential Impact
Systems that install this package are fully compromised as the package steals credential-grade environment variables and detailed host information, sending them to an attacker-controlled external server. This can lead to unauthorized access to cloud services, source code repositories, package registries, and CI/CD pipelines. The compromise extends beyond the package itself because attackers may use stolen credentials to deploy further malicious activities. Removal of the package does not guarantee remediation due to potential persistence mechanisms installed by the attacker.
Mitigation Recommendations
Immediate removal of the @galicia-toolkit/tag-manager package versions 999.0.3, 999.0.5, and 999.0.6 is required. All exposed credentials and tokens (AWS, GitHub, NPM, Node Auth, Actions tokens) must be rotated immediately from a secure, uncompromised environment. Investigate the affected systems for additional persistence or backdoors, as full compromise is likely. Avoid installing packages from untrusted or suspicious sources, especially those with inflated version numbers or unexpected scoped names. Monitor dependency resolution processes to prevent dependency confusion attacks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17691
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-q3gj-mpgg-cqpv"]
- Ecosystems
- ["npm"]
Threat ID: 6ac80fc22cdf04f65639c3b2
Added to database: 10/08/2026, 21:48:50 UTC
Last enriched: 10/08/2026, 22:13:01 UTC
Last updated: 10/08/2026, 22:13:01 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.