MAL-2026-14060
Malicious code in fastly-vcl-language-client (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (2f77be5ce1488e7867223b63fd5c90060e98d6a44325ff2f71bed2b61653d649) The package declares scripts.preinstall = 'node vishu.js', which runs unconditionally on npm install. vishu.js fetches the installer's public IP via api.ipify.org, reads os.hostname(), and collects CI runner environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT) from process.env, then POSTs/GETs the collected data to a hardcoded https://webhook.site/3c201be4-c16d-4e0c-bf9c-ccc50faa8574 endpoint. It additionally performs a DNS lookup of ping-<hostname>.<oast-collaborator-domain> to exfiltrate the hostname via DNS out-of-band. The package ships no real functionality — its metadata describes it as a 'dependency test utility package' and its name resembles an internal Fastly tool, consistent with a dependency-confusion / recon probe targeting build systems that resolve internal package names against public npm.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fastly-vcl-language-client (npm). Pin to a known-safe version or switch to an alternative.