MCPA-2026-0010
Malicious PyPI packages impersonating popular AI libraries as MCP servers (openai-mcp, langchain-core-mcp, tiktoken-mcp, instructor-mcp)
A June 2026 PyPI campaign published packages that impersonate popular AI libraries under MCP-server names: openai-mcp (impersonating the official OpenAI SDK's module structure), langchain-core-mcp (impersonating langchain-core), tiktoken-mcp (impersonating OpenAI's tiktoken), and instructor-mcp (typosquatting instructor). Flagged as malware by Amazon Inspector via OSV (MAL-2026-5317/5318/5320/5326). These names read like plausible MCP bridges for well-known libraries and are exactly what an AI assistant might suggest launching via uvx; none are published by the legitimate upstream projects. Treat every version as malicious.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | openai-mcp | >= 0 |
| pypi | langchain-core-mcp | >= 0 |
| pypi | tiktoken-mcp | >= 0 |
| pypi | instructor-mcp | >= 0 |
Identifiers
MAL-2026-5317MAL-2026-5318MAL-2026-5320MAL-2026-5326PYSEC-2026-1069PYSEC-2026-1070PYSEC-2026-1072PYSEC-2026-1075CWE-506
References
- advisory https://osv.dev/vulnerability/MAL-2026-5320
- advisory https://osv.dev/vulnerability/MAL-2026-5318
- advisory https://osv.dev/vulnerability/MAL-2026-5326
- advisory https://osv.dev/vulnerability/MAL-2026-5317
Timeline
- Published: 2026-06-08