VDB
KO

MAL-2026-14233

Malicious code in code-assist-mcp (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (093f28fd5542ee841027c5b3dc6917a42ac13dd3e0e1d3bf334e87b823886d3c) code-assist-mcp@1.0.0 runs a postinstall lifecycle script that collects host identifiers (hostname, platform, arch, Node version, package name) and POSTs them as JSON to the hardcoded host m743pyrm.instances.poc.jchunt.top at path /code-assist-mcp. The beacon fires automatically on `npm install` without user opt-in. The package name resembles Google's platform-ai code-assist tooling, consistent with a dependency-confusion or typosquat reconnaissance beacon confirming code execution on installer build machines.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / code-assist-mcp

No fixed version published yet for code-assist-mcp (npm). Pin to a known-safe version or switch to an alternative.

References