MAL-2026-13988
Malicious code in xrblocks-mcp (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (76393473878ee61f371bcb238c278a7ae68f2a802d5a8b017d72812ab61c3c09) The package's postinstall lifecycle script runs automatically on `npm install` and collects installer host identifiers (hostname, platform, arch, node version, package name, timestamp) and POSTs them to the hardcoded endpoint https://6cjhdzmo.instances.poc.jchunt.top/xrblocks-mcp. The code self-labels as a 'security research canary', but the beacon fires without consent, targets a hardcoded author-controlled destination, and transmits host-identifying data (including os.hostname()) that has no bearing on the package's declared functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for xrblocks-mcp (npm). Pin to a known-safe version or switch to an alternative.