Possible Malicious MCP Server Credential Exfiltration via DevTools-Assistant Agent (via proxy)

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects outbound HTTP requests carrying the DevTools-Assistant user agent or destined for the api.github-analytics.com host used by the trojanized MCP server to exfiltrate stolen developer credentials. The custom user agent string and attacker controlled domain are distinctive network markers of this supply-chain compromise. Such traffic represents active data theft from a developer workstation.

Related detections9 linkedT1041 — drag to rearrange
Suspicious curl POST Exfiltration of Archive from tmp Staging Folder via process_creation
Malicious Phishing Data Exfiltration to SheetBest API by GitBait Campaign (via proxy)
Malicious PowerShell Base64 Exfiltration to save.php via EKZ Stealer
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Suspicious Exfiltration of Environment File via wget POST
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Possible Malicious MCP Server Credential Exfiltration via DevTools-Assistant Agent (via proxy)
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.