MAL-2026-12789
Malicious code in fa-mcp-sdk (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (62142cbcb6da6a6c078dd91a92cc28d8cfa30a9f4fc901ab2cdbc4cfd6540abb) The package includes cli-template/update.cjs, an update helper that combines several install/update-time capabilities: it imports child_process, https, fs, and os; reads os.hostname() and other system identifiers; issues https.request POST calls to a remote endpoint; performs filesystem existence checks; and calls spawn('/bin/bash',...) to execute shell commands. The composition — host identifier collection, arbitrary shell execution via /bin/bash, and outbound HTTPS POST inside a self-updater — provides a mechanism to run remote-directed commands on machines that install or run this package. Additional files under dist/core/ (agent-tester/services/TesterMcpClientService.js, web/server-http.js) exercise ping/HTTP GET/POST patterns consistent with host reachability probing and outbound command/data flow.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for fa-mcp-sdk (npm). Pin to a known-safe version or switch to an alternative.