MCPA-2025-0012
criticalmalicious-package
@lanyer640/mcp-runcommand-server npm package backdoored with dual reverse shells
The npm MCP server @lanyer640/mcp-runcommand-server, first published as a legitimate run-command tool, was weaponized in version 1.0.6: a preinstall hook opens a reverse shell to an attacker-controlled server (45.115.38.27:2333) during `npm install`/`npx`, and a second persistent reverse shell activates whenever the MCP server runs. The functional tool behavior masked the backdoor.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @lanyer640/mcp-runcommand-server | >= 1.0.6 Malicious from 1.0.6 onward; GitHub's malware advisory marks all versions affected. Treat any installation as a full host compromise, rotate all credentials, and note the package was removed from npm on 2025-10-01 after Checkmarx's report. |
Identifiers
GHSA-xmqc-rm22-fxq6CWE-506
References
- advisory https://github.com/advisories/GHSA-xmqc-rm22-fxq6
- report https://www.koi.ai/blog/mcp-malware-wave-continues-a-remote-shell-in-backdoor
- report https://checkmarx.com/zero-post/npm-malware-alert-lanyer640-mcp-runcommand-server-with-reverse-shell/
Timeline
- Discovered: 2025-10-01
- Published: 2025-10-02
- Package withdrawn: 2025-10-01
Credits
- Koi Security
- Checkmarx Zero (Bruno Dias)