VDB
KO

MAL-2026-11198

Malicious code in mcp-search-server (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (668e6c74d0665065f6c75fb03d82071cda10cea3ad8f1cd20068cbe2c702d728) Versions published since 2026-07 contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mcp-search-server

Reasons (based on the campaign):

- other

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mcp-search-server

No fixed version published yet for mcp-search-server (pip). Pin to a known-safe version or switch to an alternative.

References