MAL-2026-14228
Malicious code in broadcast-graphics-mcp (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (48987a1a0ccff7dce1134e1a98122cd902961ac34ba623ae0e2fef62f75fe213) The package's postinstall script runs automatically on `npm install` and collects host identifiers from the installer machine (os.hostname(), platform, arch, node version, package name, npm lifecycle event, timestamp), then POSTs them as JSON to the hardcoded host `2obx43du.instances.poc.jchunt.top` at path `/broadcast-graphics-mcp`. The destination is not a first-party or user-configurable endpoint; installation of the package unconditionally leaks installer-side identity data to a remote party. The package self-labels as a 'security research canary', but self-labeling does not change the behavior: installing this package causes install-time exfiltration of host metadata to an author-controlled endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for broadcast-graphics-mcp (npm). Pin to a known-safe version or switch to an alternative.