MCPA-2025-0014
criticalmalicious-package
Malicious npm package mcp-server-everything squats the MCP reference "everything" server
The unscoped npm package mcp-server-everything (observed at 2.0.0, September 2025) is malicious and squats the name of the official MCP reference "everything" test server, which lives under the @modelcontextprotocol scope as @modelcontextprotocol/server-everything. OSV/GHSA flag every version of the unscoped name as malware (OSV MAL-2025-46986, GHSA-6j44-frpv-rvv9). MCP client configs and docs commonly launch the reference server via npx, so a missing scope prefix installs the malicious package instead. Treat every version of the unscoped npm name as malicious and use @modelcontextprotocol/server-everything.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | mcp-server-everything | >= 0 |
Identifiers
MAL-2025-46986GHSA-6j44-frpv-rvv9CWE-506
References
- advisory https://osv.dev/vulnerability/MAL-2025-46986
- advisory https://github.com/advisories/GHSA-6j44-frpv-rvv9
- web https://github.com/modelcontextprotocol/servers
Timeline
- Published: 2025-09-09