zomato-mcp@1.0.0
Malicious code in zomato-mcp (npm)
Analysis
zomato-mcp@1.0.0 is a combosquat package impersonating a Zomato MCP server. The preinstall hook collects the installer's hostname, username, current working directory, and all environment variables (base64-encoded) and POSTs them to an attacker-controlled interactsh endpoint (d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/). The preuninstall hook also beacons the hostname to the same C2. The package contains no functioning MCP server code — only a stub index.js. The env-dump exfiltrates all credentials present in environment variables (NPM_TOKEN, GITHUB_TOKEN, AWS keys, etc.). C2: d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site.
- analyzed by
- Leitwacht
- first seen
- Jun 21, 2026, 03:43 PM
- analyzed
- Jun 21, 2026, 03:43 PM
Related advisories
- @variational/common-ui@99.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- metrics-probe-9b4c@1.0.0
- @velkov/viem@2.53.1
- local-ip-helper@0.1.0
- ts-bn-lint-helper@3.1.19
- atlasora-client@1.0.0
- atlasora-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.