dbt-language-server@1.0.1
Malicious code in dbt-language-server (npm)
Analysis
dbt-language-server@1.0.1 is a combosquat (the legitimate dbt-language-server is an LSP tool for the dbt ecosystem). The package's preinstall script runs index.js automatically on npm install, which collects system reconnaissance data — hostname, home directory, username, DNS server list, the full package.json, /etc/passwd and /etc/hosts contents — and exfiltrates it via HTTPS POST to p9z268f2xv8co3wtlpujplris9y2msah[.]oastify[.]com (a Burp Collaborator / OAST blind exfiltration endpoint). The package contains no actual language-server functionality; it exists only to harvest system data on install.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 04:19 PM
- analyzed
- Jun 19, 2026, 04:19 PM
Related advisories
- simplisafe-gatsby@1.0.1
- parket-flow@3.0.1
- ts-eslinter@1.0.0
- @withgoogle/stitch-sdk@0.1.1
- new-ts-helper@9.0.2
- yianzzkf6687@1.0.3
- ts-big-ecro@3.8.1
- stitch-design@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.