LWA-2026-7049 confirmed malware

fastly-vcl-language-client@1.0.0

Malicious code in fastly-vcl-language-client (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package is a trojanized clone impersonating Fastly VCL tooling. On npm install, the preinstall hook runs vishu.js which collects the installer's public IP address (via api[.]ipify[.]org), hostname, and CI/CD environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT) and exfiltrates them to webhook[.]site/3c201be4-c16d-4e0c-bf9c-ccc50faa8574 via HTTPS GET and to an oastify[.]com collaborator domain via DNS lookup.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 08:04 PM
analyzed
Jul 22, 2026, 08:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.