message-compiler@9.2.0
Malicious code in message-compiler (npm)
Analysis
The package's preinstall hook runs vishu.js, which on install exfiltrates host and CI metadata to attacker-controlled endpoints. It fetches the machine's public IP from api[.]ipify[.]org, sends an HTTPS request to hxxps://webhook[.]site/32113f06-42ab-454b-a58f-5a8ea6333c6d with the IP and CI environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT) appended as query parameters, and performs a DNS lookup against ping-<hostname>.your-collab-domain[.]oastify[.]com (a Burp Collaborator interaction domain). The package has no legitimate function requiring network access on install.
- analyzed by
- Leitwacht
- first seen
- Aug 23, 2026, 04:55 PM
- analyzed
- Aug 23, 2026, 04:55 PM
Related advisories
- @finaxis/common-js@0.3.3
- sme-rko-finance-front-operations-notifications-impl@35.8.1
- dolyame-ui-cardlogo@35.8.1
- dolyame-ui-contextmenu@35.8.1
- dolyame-ui-contenteditable@35.8.1
- dolyame-ui-mediainfohoc@35.8.1
- dolyame-ui-inputtime@35.8.1
- dolyame-ui-selectaccount@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.