LWA-2026-5775 MAL-2026-6367 ↗ confirmed malware

dbt-language-server@1.0.1

Malicious code in dbt-language-server (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

dbt-language-server@1.0.1 is a combosquat (the legitimate dbt-language-server is an LSP tool for the dbt ecosystem). The package's preinstall script runs index.js automatically on npm install, which collects system reconnaissance data — hostname, home directory, username, DNS server list, the full package.json, /etc/passwd and /etc/hosts contents — and exfiltrates it via HTTPS POST to p9z268f2xv8co3wtlpujplris9y2msah[.]oastify[.]com (a Burp Collaborator / OAST blind exfiltration endpoint). The package contains no actual language-server functionality; it exists only to harvest system data on install.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 04:19 PM
analyzed
Jun 19, 2026, 04:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.