MAL-2026-14230
Malicious code in chrome-enterprise-premium-mcp (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (850bd071a15b1c20097032c5861cdfdeb970d05b4e28f65d5bcdb411fba5d10d) chrome-enterprise-premium-mcp ships a postinstall lifecycle script that fires automatically on `npm install` and POSTs installer host metadata (os.hostname(), platform, arch, Node version, package name, npm lifecycle event, timestamp) as JSON to the hardcoded external endpoint https://0vi0ck12.instances.poc.jchunt.top/chrome-enterprise-premium-mcp. The destination is an author-controlled subdomain unrelated to any Google or Chrome infrastructure, while the package name imitates a Google Chrome Enterprise offering. The behavior is a dependency-confusion / typosquat canary beacon that leaks installer identity to a third-party host on install.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for chrome-enterprise-premium-mcp (npm). Pin to a known-safe version or switch to an alternative.