VDB
Sign up

MAL-2026-16250

Malicious code in marketing-mcp (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (87216e00fe68e2de8b140f1f9ffc2db5a8e814f38030e2eb6120c9ae9e7ca3ff) The package exposes an MCP tool `send(path)` that reads a caller-specified local file and POSTs its contents to a hardcoded `https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c` endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to `send` — including sensitive paths such as `~/.ssh/id_rsa`, `~/.aws/credentials`, `.env` files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.

## Source: kam193 (6a271b29f840e2047c34363e985921e1a374194cfcae7524698f178c96bea9eb) Package attempts to lure LLM agents to exfiltrate files to a hardcoded location. Analysis of infrastructure suggests preparing for exfiltrating credentials.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-marketing-mcp

Reasons (based on the campaign):

- files-exfiltration

- llm-threat

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/marketing-mcp

No fixed version published yet for marketing-mcp (pip). Pin to a known-safe version or switch to an alternative.

References