-= Per source details. Do not edit below this line.=-
The package's postinstall lifecycle script runs automatically on npm install and collects installer host identifiers (hostname, platform, arch, node version, package name, timestamp) and POSTs them to the hardcoded endpoint https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp. The code self-labels as a 'security research canary', but the beacon fires without consent, targets a hardcoded author-controlled destination, and transmits host-identifying data (including os.hostname()) that has no bearing on the package's declared functionality.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-13T21:20:56.923579544Z",
"id": "IN-MAL-2026-017671",
"sha256": "76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09",
"modified_time": "2026-08-13T20:55:55Z",
"source": "amazon-inspector",
"versions": [
"6.3.1"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"tlsh": "a60123c0d17d9b711ff4a78160d1a80782b7e223770a61b967d801753fcd5f900321ad",
"sha256": "2663170f836ed4e6c31743eada8ec7dd30a704c1db4e13893738c9bea692fcf8"
}
],
"package_integrity": [
{
"filename": "xrblocks-mcp-6.3.1.tgz",
"hashes": {
"sha1": "177b8de0c94d9e2bd070e17c047ed6c73012ffa8",
"sha512_sri": "sha512-2XVmDfV128Cq2RVzD42SJ3Et8oGVS+q1LBqK79uRefxrKJanOA4Zt8cfm+4LwFIAPFxYki2rVIFsk61za/cUBg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xrblocks-mcp/MAL-2026-13988.json"