LWA-2026-7049 confirmed malware
fastly-vcl-language-client@1.0.0
Malicious code in fastly-vcl-language-client (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The package is a trojanized clone impersonating Fastly VCL tooling. On npm install, the preinstall hook runs vishu.js which collects the installer's public IP address (via api[.]ipify[.]org), hostname, and CI/CD environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT) and exfiltrates them to webhook[.]site/3c201be4-c16d-4e0c-bf9c-ccc50faa8574 via HTTPS GET and to an oastify[.]com collaborator domain via DNS lookup.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 08:04 PM
- analyzed
- Jul 22, 2026, 08:04 PM
Related advisories
- content-publisher-sdks@1.0.1
- tidal-embed-player@1.0.1
- forge-extended@1.0.1
- knowledge-grader@1.0.1
- chai-as-stringify@7.0.2
- xerohub-discord-voice-v2@1.8.0
- chai-as-format@2.3.5
- chai-as-deployer@2.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.