matlab-azure-devops-extension@1.1.1
Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 4:09 AM UTC
OSV ID
MAL-2026-12400
Ecosystem
npm
Summary
The package's preinstall script (node index.js) auto-executes on npm install and collects host identifiers (os.hostname(), os.userInfo().username, home directory, DNS servers) along with the contents of /etc/passwd and /etc/hosts, then POSTs them via HTTPS to a hardcoded Burp Collaborator subdomain at 2ru8qr34u3so6bnti176tzt30u6muci1.oastify.com. The package name mimics an Azure DevOps MATLAB extension but ships no legitimate functionality (empty author, empty description); the package exists only to run the exfil beacon. Consistent with a dependency-confusion / recon probe.
Source: amazon-inspector (ecc42778bb54bfdea5784d5dcb68cf43c89def3dbaeddba1d1a6bd2850cb174b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.