LWA-2026-4815 MAL-2026-5891 ↗ confirmed malware

atlassian-forge-skills@29.1.0

Malicious code in atlassian-forge-skills (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.004 · DNST1041 · Exfiltration Over C2 Channel

Analysis

Package `atlassian-forge-skills` combosquats the official Atlassian Forge SDK. The `preinstall` lifecycle hook runs `index.js`, which uses `os.hostname()` to read the installer's machine hostname, constructs the domain `{hostname}.zcagyqqmvnmgsklstrrr6xo2715tov7wz[.]oast[.]fun`, and sends a DNS lookup to that attacker-controlled interactsh callback server — exfiltrating the machine identity to the attacker. The publisher (`lapdeplap` / `[account]`) is a throwaway identity not affiliated with Atlassian. IOC: oast[.]fun domain `zcagyqqmvnmgsklstrrr6xo2715tov7wz[.]oast[.]fun`.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 05:40 PM
analyzed
Jun 12, 2026, 05:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.