MAL-2026-10541

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/proxy-seller-mcp/MAL-2026-10541.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10541
Published
2026-07-14T03:47:41Z
Modified
2026-07-14T04:46:57Z
Summary
Malicious code in proxy-seller-mcp (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6ae92b460e6db9195467e69567fadc3286877ea8e6b121448288a4f77acf5201)

Package is published as proxy-seller-mcp with author: "Proxy-Seller" in package.json and a README directing users to obtain an API key at https://front-v2.proxy-seller.com — the legitimate Proxy-Seller domain. However, the hardcoded default API base URL in dist/config.js line 13 is https://the assessment.bydloss.mom, an unrelated domain, and dist/stdio.js line 7 instructs users to fetch their API key from https://the assessment.bydloss.mom/personal/api. Every MCP tool invocation sends the caller's Proxy-Seller API key (embedded in the URL path) along with proxy-management operations (orders, balance top-ups, credential retrieval, list/replace/delete) to bydloss.mom rather than to Proxy-Seller. The repository field points at a personal GitHub account (dmitriyn3679/mcp), not a Proxy-Seller organization. The combination of vendor-name impersonation in package metadata, README pointing to the legitimate vendor, and code defaulting to an unrelated domain is deliberate misdirection — any developer who installs and configures this MCP will hand over live Proxy-Seller credentials and proxy-account control to the operator of bydloss.mom on first tool use.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-010380",
            "import_time": "2026-07-14T04:32:00.001056239Z",
            "modified_time": "2026-07-14T03:47:41Z",
            "sha256": "6ae92b460e6db9195467e69567fadc3286877ea8e6b121448288a4f77acf5201",
            "source": "amazon-inspector",
            "versions": [
                "0.1.7"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / proxy-seller-mcp

Package

Name
proxy-seller-mcp
View open source insights on deps.dev
Purl
pkg:npm/proxy-seller-mcp

Affected ranges

Affected versions

0.*
0.1.7

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/config.js",
            "sha256": "59c4a474674f1380fae046ba1b3bf6d8c84bdddf45445ca9b9c8e72ec6edfd45",
            "tlsh": "1f011548d5bb28aa06325f94047f9323f6bc3003390591dc736cb2183f5193d42f3969"
        },
        {
            "path": "package.json",
            "sha256": "47bef941a1e08055a27bec6276fb3b02cfe9036475560b61cc423d4437ef7e24",
            "tlsh": "4731a929cab65c7747cd56c0a86a2182b72884478d18fd0933d6412c4f9d06f96ff2ec"
        }
    ],
    "package_integrity": [
        {
            "filename": "proxy-seller-mcp-0.1.7.tgz",
            "hashes": {
                "sha1": "3b4ed46e9d9840c85b1538e4eca6601b9cd14a1e",
                "sha512_sri": "sha512-ZA+4ev697oa858arEZ99J9HuwS04dMZJh7xEn40aVCXqFlJVeyHQw4a03BCx46rmC2mJLxxPj+AhqKik1d2Dug=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/proxy-seller-mcp/MAL-2026-10541.json"