MAL-2026-13988

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xrblocks-mcp/MAL-2026-13988.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13988
Published
2026-08-13T20:55:55Z
Modified
2026-08-13T21:30:27.304780881Z
Summary
Malicious code in xrblocks-mcp (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09)

The package's postinstall lifecycle script runs automatically on npm install and collects installer host identifiers (hostname, platform, arch, node version, package name, timestamp) and POSTs them to the hardcoded endpoint https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp. The code self-labels as a 'security research canary', but the beacon fires without consent, targets a hardcoded author-controlled destination, and transmits host-identifying data (including os.hostname()) that has no bearing on the package's declared functionality.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-13T21:20:56.923579544Z",
            "id": "IN-MAL-2026-017671",
            "sha256": "76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09",
            "modified_time": "2026-08-13T20:55:55Z",
            "source": "amazon-inspector",
            "versions": [
                "6.3.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / xrblocks-mcp

Package

Affected ranges

Affected versions

6.*
6.3.1

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "postinstall.js",
            "tlsh": "a60123c0d17d9b711ff4a78160d1a80782b7e223770a61b967d801753fcd5f900321ad",
            "sha256": "2663170f836ed4e6c31743eada8ec7dd30a704c1db4e13893738c9bea692fcf8"
        }
    ],
    "package_integrity": [
        {
            "filename": "xrblocks-mcp-6.3.1.tgz",
            "hashes": {
                "sha1": "177b8de0c94d9e2bd070e17c047ed6c73012ffa8",
                "sha512_sri": "sha512-2XVmDfV128Cq2RVzD42SJ3Et8oGVS+q1LBqK79uRefxrKJanOA4Zt8cfm+4LwFIAPFxYki2rVIFsk61za/cUBg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xrblocks-mcp/MAL-2026-13988.json"