Malicious code in optimizely-starter-kit-for-fastly-compute (npm)
The npm package 'optimizely-starter-kit-for-fastly-compute' version 1.0.1 contains malicious code that executes automatically during installation. The embedded script collects sensitive host information and system files, then exfiltrates this data to an external server. This package is a typosquatting or dependency confusion attempt mimicking legitimate tooling. Systems with this package installed should be considered fully compromised, and all secrets should be rotated immediately.
AI Analysis
Technical Summary
The 'optimizely-starter-kit-for-fastly-compute' npm package version 1.0.1 declares a 'preinstall' script that runs 'index.js' automatically on npm install. This script gathers host identifiers such as hostname, user info, home directory, DNS servers, and contents of package.json, and reads sensitive files like /etc/passwd and /etc/hosts. It then sends this collected data via HTTPS POST to a Burp Collaborator out-of-band domain, indicating data exfiltration. The package name is crafted to resemble legitimate Optimizely/Fastly Compute tooling, consistent with a dependency confusion or typosquatting attack vector. The presence of this package implies full system compromise.
Potential Impact
Installation of this package results in automatic execution of malicious code that collects and exfiltrates sensitive system information and files. This compromises confidentiality and potentially integrity of the affected system. Because the attacker may have full control, all stored secrets and keys on the compromised machine are at risk and should be considered exposed.
Mitigation Recommendations
Remove the 'optimizely-starter-kit-for-fastly-compute' package immediately. Rotate all secrets and keys that were stored on the compromised system from a separate, trusted machine. Due to the high likelihood of full system compromise, further forensic analysis and remediation may be necessary. There is no official patch or fix; the package itself is malicious and should not be used.
Malicious code in optimizely-starter-kit-for-fastly-compute (npm)
Description
The npm package 'optimizely-starter-kit-for-fastly-compute' version 1.0.1 contains malicious code that executes automatically during installation. The embedded script collects sensitive host information and system files, then exfiltrates this data to an external server. This package is a typosquatting or dependency confusion attempt mimicking legitimate tooling. Systems with this package installed should be considered fully compromised, and all secrets should be rotated immediately.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'optimizely-starter-kit-for-fastly-compute' npm package version 1.0.1 declares a 'preinstall' script that runs 'index.js' automatically on npm install. This script gathers host identifiers such as hostname, user info, home directory, DNS servers, and contents of package.json, and reads sensitive files like /etc/passwd and /etc/hosts. It then sends this collected data via HTTPS POST to a Burp Collaborator out-of-band domain, indicating data exfiltration. The package name is crafted to resemble legitimate Optimizely/Fastly Compute tooling, consistent with a dependency confusion or typosquatting attack vector. The presence of this package implies full system compromise.
Potential Impact
Installation of this package results in automatic execution of malicious code that collects and exfiltrates sensitive system information and files. This compromises confidentiality and potentially integrity of the affected system. Because the attacker may have full control, all stored secrets and keys on the compromised machine are at risk and should be considered exposed.
Mitigation Recommendations
Remove the 'optimizely-starter-kit-for-fastly-compute' package immediately. Rotate all secrets and keys that were stored on the compromised system from a separate, trusted machine. Due to the high likelihood of full system compromise, further forensic analysis and remediation may be necessary. There is no official patch or fix; the package itself is malicious and should not be used.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14138
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-8pfr-f8q3-mr5x"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a9f9110acd9273b49ff2ac7
Added to database: 09/08/2026, 04:37:36 UTC
Last enriched: 09/08/2026, 05:24:57 UTC
Last updated: 09/08/2026, 17:11:47 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.