MCPA-2026-0004
criticalmalicious-package
ray-mcp-server 0.2.1 shipped malicious code (Hades/Shai-Hulud PyPI campaign)
PyPI package ray-mcp-server version 0.2.1 contained malicious code delivered through a setup.pth payload, part of the Hades campaign hitting PyPI packages. Published as PYSEC-2026-1074 / OSV MAL-2026-5325. Only 0.2.1 is listed as affected; installations pinned to other versions should still verify their environment, and machines that installed 0.2.1 (e.g. via `uvx ray-mcp-server`) should rotate secrets.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | ray-mcp-server | >= 0.2.1, <= 0.2.1 |
Identifiers
PYSEC-2026-1074MAL-2026-5325CWE-506
References
- advisory https://osv.dev/vulnerability/PYSEC-2026-1074
- article https://www.stepsecurity.io/blog/the-hades-campaign-pypi-packages
- article https://www.endorlabs.com/learn/shai-hulud-hades-wave-hits-six-pypi-bioinformatics-packages
Timeline
- Published: 2026-07-07