VDB
KO

MAL-2026-14138

Malicious code in optimizely-starter-kit-for-fastly-compute (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (72b7bcd65cbf07a90130de5e4a29fb72bc99badb287a1e1dc7373c288a1ae0be) package.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, __dirname, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to aguu8c8gjyt4anjao3nhru1mgdm5avyk.oastify.com, a Burp Collaborator out-of-band interaction subdomain. The package name resembles legitimate Optimizely/Fastly Compute tooling, consistent with a dependency-confusion or typosquat exfiltration beacon.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / optimizely-starter-kit-for-fastly-compute

No fixed version published yet for optimizely-starter-kit-for-fastly-compute (npm). Pin to a known-safe version or switch to an alternative.

References