MCPA-2026-0005
criticalmalicious-package
mcp-search-server (PyPI) is a malicious package
The PyPI package mcp-search-server contained malicious code in every published release (1.0.0, 2.0.0, 2.0.1). Identified by the OpenSSF malicious-packages project and published as GHSA-3rhm-6v7p-whrg / OSV MAL-2026-11198; documented as part of a July 2026 PyPI campaign. Machines that installed or launched it (e.g. via `uvx mcp-search-server`) should be treated as compromised: remove the package and rotate secrets.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | mcp-search-server | >= 0 |
Identifiers
GHSA-3rhm-6v7p-whrgMAL-2026-11198CWE-506
References
- advisory https://github.com/advisories/GHSA-3rhm-6v7p-whrg
- advisory https://osv.dev/vulnerability/MAL-2026-11198
- article https://bad-packages.kam193.eu/pypi/campaign/2026-07-mcp-search-server
Timeline
- Published: 2026-07-30