MAL-2026-11198

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/mcp-search-server/MAL-2026-11198.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11198
Published
2026-07-30T17:30:32Z
Modified
2026-08-04T23:05:47Z
Summary
Malicious code in mcp-search-server (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (03f5e3f7f8e637ac814a5040b2e61c8608327f73b1c44352e694848a8c35e181)

On import, server.py starts a background thread that issues an HTTP GET to the hardcoded bare-IP endpoint http://187.127.73.142:8777 carrying a per-host identifier derived from os.uname().nodename hashed with the current time (SWARM_ID). The beacon fires unconditionally under _swarm_connect(), labelled in comments as 'Silent background connection' / 'Auto-connect on import (silent)'. Separately, the advertised web_search and image_search tools route all caller-supplied query text over cleartext HTTP to the same hardcoded bare IP (http://187.127.73.142:8080/search), presented as an 'uncensored SearXNG' instance, with no configuration option to redirect to a different backend. The README frames the beacon as an 'optional distributed compute swarm', but the code contains no opt-in flag and runs the connection on every import. The result is a hardcoded, unconfigurable relay of both host identity and user search queries to an author-controlled bare IP over plain HTTP.

Source: kam193 (75c59285ee1a5a83447815e7402410ccfca6a287e0c36d61bcfda3d55396f608)

Versions published in 2026-07 (after the package was removed by the original author and the name was re-registered by another) contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mcp-search-server

Reasons (based on the campaign):

  • other
Database specific
{
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-07-mcp-search-server/mcp-search-server",
            "import_time": "2026-07-30T18:02:01.370894824Z",
            "modified_time": "2026-07-30T17:33:32.596269Z",
            "sha256": "668e6c74d0665065f6c75fb03d82071cda10cea3ad8f1cd20068cbe2c702d728",
            "source": "kam193",
            "versions": [
                "1.0.0",
                "2.0.0",
                "2.0.1"
            ]
        },
        {
            "id": "pypi/2026-07-mcp-search-server/mcp-search-server",
            "import_time": "2026-07-30T21:30:36.849265952Z",
            "modified_time": "2026-07-30T17:33:32.596269Z",
            "sha256": "75c59285ee1a5a83447815e7402410ccfca6a287e0c36d61bcfda3d55396f608",
            "source": "kam193",
            "versions": [
                "1.0.0",
                "2.0.0",
                "2.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-011223",
            "import_time": "2026-08-04T22:30:05.914384026Z",
            "modified_time": "2026-08-04T21:50:08Z",
            "sha256": "abc86f89945197c8cfbe8d05fbc6a1b4ad62950800c7b3a83c7fe317e330b334",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-011221",
            "import_time": "2026-08-04T22:30:05.812458371Z",
            "modified_time": "2026-08-04T21:49:49Z",
            "sha256": "03f5e3f7f8e637ac814a5040b2e61c8608327f73b1c44352e694848a8c35e181",
            "source": "amazon-inspector",
            "versions": [
                "2.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-011273",
            "import_time": "2026-08-04T22:30:08.404487907Z",
            "modified_time": "2026-08-04T21:57:35Z",
            "sha256": "5e1fc6ecdee1eb65dd43b732ab380cfc31ba7e9bcf7af3057222fc9c2e5ccccc",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / mcp-search-server

Package

Name
mcp-search-server
View open source insights on deps.dev
Purl
pkg:pypi/mcp-search-server

Affected ranges

Affected versions

1.*
1.0.0
2.*
2.0.0
2.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "server.py",
            "sha256": "15f31d27d0f3b8fa539d533c7537d38a962f0de8c89b6336710527ea30109af4",
            "tlsh": "82917452fc56682396faa5586478e1c2777d664761046c7cfdec8a380f4ccb354b8298"
        }
    ],
    "package_integrity": [
        {
            "filename": "mcp_search_server-2.0.0-py3-none-any.whl",
            "hashes": {
                "blake2b_256": "df2158a6364e19d22c4e34fbff33b41c9463acc16dcb751bf5205cb5598589a5",
                "md5": "17b519831940bbf76d6f6fa001acda90",
                "sha256": "dc2f6cc8694e60135d3a9fe047e2d767909e5ac93efeb3b4cd3600bb7d965903"
            }
        },
        {
            "filename": "mcp_search_server-2.0.0.tar.gz",
            "hashes": {
                "blake2b_256": "414d932d959b961d02b8e5c6b4586a7ae0a1b52aa9e3a06556ffbfcc23fb6966",
                "md5": "c368a8a5592eb4b980ef07221772fb16",
                "sha256": "9b70ab1f5a98a658e0002b879c2b8de894045ba72ff60eb914c061a989a1f1b3"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/mcp-search-server/MAL-2026-11198.json"