LWA-2026-6451 confirmed malware

gitlens@9.4.1

Malicious code in gitlens (npm)

Analysis

Combosquat package impersonating the GitLens name. The preinstall hook executes `curl` to an OAST callback domain (bt8hbz0owdan31qvdap2u5b8izoqcg05[.]oastify[.]com) on install, beaconing the installer's IP address and environment to an attacker-controlled interaction server. The package contains no functional code beyond a stub.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 08:56 AM
analyzed
Jul 8, 2026, 08:56 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.