matlab-azure-devops-extension@1.0.1
Malicious code in matlab-azure-devops-extension (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS server list, /etc/passwd contents, /etc/hosts contents, and package.json metadata, then POSTs all of this data to 2ru8qr34u3so6bnti176tzt30u6muci1[.]oastify[.]com over HTTPS. The package name combines "matlab" and "azure-devops-extension" to impersonate a legitimate DevOps integration tool but has no repository or description.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 07:28 PM
- analyzed
- Jul 28, 2026, 07:28 PM
Related advisories
- wolverinechat@1.0.1
- blots@2.1.0
- voicemail@1.0.1
- toll_free@1.0.1
- @adominadmininstr/fmt-date-helper@1.0.0
- @adominadmininstr/date-util-helper@1.0.0
- array-sort-helper@1.0.0
- json-to-table-util@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.