MAL-2026-14233
Malicious code in code-assist-mcp (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (093f28fd5542ee841027c5b3dc6917a42ac13dd3e0e1d3bf334e87b823886d3c) code-assist-mcp@1.0.0 runs a postinstall lifecycle script that collects host identifiers (hostname, platform, arch, Node version, package name) and POSTs them as JSON to the hardcoded host m743pyrm.instances.poc.jchunt.top at path /code-assist-mcp. The beacon fires automatically on `npm install` without user opt-in. The package name resembles Google's platform-ai code-assist tooling, consistent with a dependency-confusion or typosquat reconnaissance beacon confirming code execution on installer build machines.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for code-assist-mcp (npm). Pin to a known-safe version or switch to an alternative.