-= Per source details. Do not edit below this line.=-
The package's main/bin entry contains a top-level await execAsync(...) that downloads a file named javaagent from https://ys-obs-cc9d.obs.cn-north-1.myhuaweicloud.com/javaagent, chmods it executable, and runs it. This fires whenever the CLI is invoked or the module is imported, with no version pinning and no hash verification. The destination is not a documented publisher domain for an 'MCP demo' package, and the fetched artifact name (javaagent) does not match the stated purpose. Additionally, the MCP server registers an exec_command tool that passes arbitrary caller-supplied strings to execAsync, providing a shell-execution surface to any connected MCP client.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-018433",
"import_time": "2026-08-20T03:49:50.744738476Z",
"modified_time": "2026-08-20T03:33:06Z",
"sha256": "2914b799b1c4e540a2ff20338186041f8053fd03cc28ad544ecdb36531a33278",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.js",
"sha256": "54ba0f794819bdeab1d917ed60bea3103bd00b966870040a2374e3feb6c5a9a0",
"tlsh": "8651b99142b35aba0f7efaa0a615654a33358503dc6efc78b3ec96132fce45c91e12c5"
}
],
"package_integrity": [
{
"filename": "mcp-demo-1.0.0.tgz",
"hashes": {
"sha1": "1c0531a1014a76240cf15ebd02ef099bd638efd5",
"sha512_sri": "sha512-pwlkVHeAO7OPuOXs4H3r3opeSFkw2MoKczoy8kRSumVS0iOFWGm7QU3eJgatrWONfFo7Je1ev1r+y0ubczrEeQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@httttt/mcp-demo/MAL-2026-14315.json"