{"id":"MAL-2026-6367","summary":"Malicious code in dbt-language-server (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b15387169de77b4c18baf8c3f4d27156085bd06d96d0a27879545c3f0358dba8)\npackage.json declares a preinstall hook (`node index.js`) that runs automatically on `npm install`. index.js collects installer-side reconnaissance data — hostname, username, home directory, DNS servers, package metadata — and reads the contents of /etc/passwd and /etc/hosts from the installer machine, then POSTs the bundle over HTTPS to `p9z268f2xv8co3wtlpujplris9y2msah.oastify.com`, a Burp Collaborator subdomain used for out-of-band exfiltration. The package has empty author/description/license fields and ships no functionality beyond this payload. The name `dbt-language-server` shadows a plausible internal/private package, consistent with a dependency-confusion attack targeting organizations that use a dbt-related internal tool.\n","modified":"2026-06-24T05:01:22.336422445Z","published":"2026-06-24T04:07:56Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-007419","import_time":"2026-06-24T04:54:33.997157579Z","modified_time":"2026-06-24T04:07:56Z","sha256":"b15387169de77b4c18baf8c3f4d27156085bd06d96d0a27879545c3f0358dba8","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dbt-language-server/v/1.0.1"}],"affected":[{"package":{"name":"dbt-language-server","ecosystem":"npm","purl":"pkg:npm/dbt-language-server"},"versions":["1.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"8a32818201c3135cbf797bebbd213fa1f40a085910e8376cedfd8e028ef97f1e","tlsh":"36412395a2c917330dd210c06a0c70813399fa777269e8d076cf42969f869f8bb326f3"},{"path":"package.json","sha256":"b5f378ea991eb7835ad9c2281242becfbf3b1d20f6be189461c3917dfcc0e8e8","tlsh":"08d0a7304d21953365c106a21c6ba44773618f2f14047c0863cb582d91cf67798ff31c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dbt-language-server/MAL-2026-6367.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}