67.25.6

    Salesforce CLI

    Provides integration with the Salesforce CLI

    Rank#-4379
    Publisher salesforceRegistry openvsx626,883Last scanned Sep 30, 2026, 05:42 PMRegistryHomepageGitHub
    Created
    9 years ago
    Last commit
    5 days ago
    Latest release
    v67.20.02 weeks ago

    Security Findings

    13

    Hardcoded C2 with exfil/exec behavior

    MaliciousScanner

    Contacts a hardcoded public IP paired with download/eval/sensitive-access/upload

    Hardcoded C2 infrastructure

    SuspiciousScanner

    Hardcoded public IP address: 204.93.223.144

    pull_request_target with secrets

    MaliciousLineage

    [.github/workflows/docOnlyAutoMerge.yml] pull_request_target with secrets

    Sensitive file access

    SuspiciousScanner

    Access to sensitive file: /etc/passwd

    Suspicious outbound hosts7×

    SuspiciousScanner

    Outbound URLs to non-allowlisted host(s): cve.mitre.org, datatracker.ietf.org, json-schema.org, man7.org, nvlpubs.nist.gov, soap.sforce.com, tools.ietf.org, www.cl.cam.ac.uk

    Outbound URLs to non-allowlisted host(s): chromedevtools.github.io, datatracker.ietf.org, docs.libuv.org, fetch.spec.whatwg.org, http2.github.io, linux.die.net, man7.org, qvis.quictools.info

    Outbound URLs to non-allowlisted host(s): [fe80:0:0:0:0:0:0:1], [fe80::1], bmeck.github.io, chromedevtools.github.io, cve.mitre.org, developer.chrome.com, dzone.com, es5.github.io

    Outbound URLs to non-allowlisted host(s): registry.yarnpkg.com, soap.sforce.com, www.ecma-international.org

    Outbound URLs to non-allowlisted host(s): instancename.lightning.force.com, mydomainname.lightning.force.com, mydomainname.my.site.com, soap.sforce.com, www.nist.gov, www.oasis-open.org

    Outbound URLs to non-allowlisted host(s): soap.sforce.com

    Outbound URLs to non-allowlisted host(s): 794testsite.my.site.com, breeze.aimon.applicationinsights.io, json-schema.org, soap.sforce.com

    Coverage evasion (executable content over cap)

    SuspiciousScanner

    2667 executable file(s) totalling 3062413 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (80.35% of code-bearing bytes reached the rules)

    Install-lifecycle script shipped

    SuspiciousScanner

    package.json preinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): node ../../scripts/require-root-install.js