optimizely-starter-kit-for-fastly-compute @1.0.1
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC
OSV ID
MAL-2026-14138
Ecosystem
npm
Summary
package.json declares preinstall: node index.js , causing index.js to run automatically on npm install . The script collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, __dirname, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the payload over HTTPS to aguu8c8gjyt4anjao3nhru1mgdm5avyk.oastify.com, a Burp Collaborator out-of-band interaction subdomain. The package name resembles legitimate Optimizely/Fastly Compute tooling, consistent with a dependency-confusion or typosquat exfiltration beacon.
Source: amazon-inspector (72b7bcd65cbf07a90130de5e4a29fb72bc99badb287a1e1dc7373c288a1ae0be)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.