LWA-2026-7199 MAL-2026-12400 ↗ confirmed malware

matlab-azure-devops-extension@1.0.1

Malicious code in matlab-azure-devops-extension (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS server list, /etc/passwd contents, /etc/hosts contents, and package.json metadata, then POSTs all of this data to 2ru8qr34u3so6bnti176tzt30u6muci1[.]oastify[.]com over HTTPS. The package name combines "matlab" and "azure-devops-extension" to impersonate a legitimate DevOps integration tool but has no repository or description.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 07:28 PM
analyzed
Jul 28, 2026, 07:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.