MAL-2026-16061

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@yongot/canary-mcp-isolation/MAL-2026-16061.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16061
Published
2026-09-09T01:42:00Z
Modified
2026-09-21T22:30:44Z
Summary
Malicious code in @yongot/canary-mcp-isolation (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6ff9f45262c13bea579ed092cabfb043896d60c89787301b73eef78848802574)

package.json declares a postinstall script that runs beacon.js, and index.js also requires beacon.js on load. beacon.js POSTs the installer's os.hostname(), a persisted run marker read from os.tmpdir(), and stage info to a hardcoded webhook.site collector at https://webhook.site/b76376f8-118e-44f1-a5ee-8a73f55b137b, and additionally probes the cloud instance metadata service at 169.254.169.254 and metadata.google.internal with the Metadata-Flavor: Google header. The exfiltration fires automatically on npm install and again on import, with no consent gating and no caller-configurable destination. The package's self-description as a benign canary for authorized testing does not change the behavior: any environment that installs this package sends host identifiers and cloud-metadata reachability to a third-party webhook endpoint controlled by whoever holds that UUID.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-019752",
            "import_time":  "2026-09-09T01:51:49.354035Z",
            "modified_time":  "2026-09-09T01:42:00Z",
            "sha256":  "1fed7c0ff512ccb2e87647a41a92653138ff50b2be906043aba86ce76b49e340",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020282",
            "import_time":  "2026-09-21T22:16:51.576688791Z",
            "modified_time":  "2026-09-21T21:38:04Z",
            "sha256":  "ed78c5cee612314e8f9f631cfc25aec0b6ea911e5390c335a806b28cef4662e4",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020281",
            "import_time":  "2026-09-21T22:16:51.528953781Z",
            "modified_time":  "2026-09-21T21:37:53Z",
            "sha256":  "6ff9f45262c13bea579ed092cabfb043896d60c89787301b73eef78848802574",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @yongot/canary-mcp-isolation

Package

Name
@yongot/canary-mcp-isolation
View open source insights on deps.dev
Purl
pkg:npm/%40yongot/canary-mcp-isolation

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "beacon.js",
            "sha256":  "12a3c5bf3d7c959c1ffd2617df3fca75d18820511f2e457c2bc40a8db9b20b9b",
            "tlsh":  "634144eb62f4b2224af2a2dc836795076327e341b188efd4f8dc06a21fd557855835f8"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "canary-mcp-isolation-1.0.1.tgz",
            "hashes":  {
                "sha1":  "a3b72d630efb5c99354517498eee2d82818ac0db",
                "sha512_sri":  "sha512-oZtCzQWOENK1+S7aX2dlXCORyWLm+2++P8R3sGkwTLZ2K3Z1oonexham4g2D2emR3Fy0RctxL4L3MWyy3cJX7A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@yongot/canary-mcp-isolation/MAL-2026-16061.json"