Skip to content

MCPA-2026-0009

criticalmalicious-package

Malicious npm packages squatting official MCP reference server names (mcp-server-fetch et al.)

A June 2026 campaign published ten unscoped npm packages squatting the names of official MCP reference servers (mcp-server-fetch, mcp-server-git, mcp-server-github, mcp-server-figma, mcp-server-notion, mcp-server-postgres, mcp-server-redis, mcp-server-sentry, mcp-server-sequential-thinking, mcp-server-supabase). Each declares a postinstall hook and uses the same file as main/bin, so the payload runs on npm install, require(), and npx invocation alike, exfiltrating host and environment data to a hardcoded workers.dev endpoint. AI coding agents and MCP client configs commonly launch these exact names via `npx mcp-server-*`; the legitimate reference servers live under the @modelcontextprotocol scope (e.g. @modelcontextprotocol/server-github) or, for fetch/git, on PyPI. Treat every version of the unscoped npm names as malicious.

Affected packages

EcosystemPackageAffected versions
npmmcp-server-fetch
>= 0
npmmcp-server-figma
>= 0
npmmcp-server-git
>= 0
npmmcp-server-github
>= 0
npmmcp-server-notion
>= 0
npmmcp-server-postgres
>= 0
npmmcp-server-redis
>= 0
npmmcp-server-sentry
>= 0
npmmcp-server-sequential-thinking
>= 0
npmmcp-server-supabase
>= 0

Identifiers

MAL-2026-5476MAL-2026-5477MAL-2026-5478MAL-2026-5479MAL-2026-5480MAL-2026-5481MAL-2026-5482MAL-2026-5483MAL-2026-5484MAL-2026-5485GHSA-88f3-qjxp-rpp3GHSA-cxx6-mmxm-vfm4GHSA-hmxw-q2gh-p268GHSA-mmcr-x94x-c3mpGHSA-mx42-9xv4-vm87GHSA-62p7-frf5-h7p2GHSA-2rvc-xw64-r74hGHSA-28qv-2m9q-wm2pGHSA-w69h-vf37-j4w6GHSA-48pr-c89h-69q7CWE-506

References

Timeline

  • Published: 2026-06-09

← All advisories