Skip to content

MCPA-2026-0010

criticalmalicious-package

Malicious PyPI packages impersonating popular AI libraries as MCP servers (openai-mcp, langchain-core-mcp, tiktoken-mcp, instructor-mcp)

A June 2026 PyPI campaign published packages that impersonate popular AI libraries under MCP-server names: openai-mcp (impersonating the official OpenAI SDK's module structure), langchain-core-mcp (impersonating langchain-core), tiktoken-mcp (impersonating OpenAI's tiktoken), and instructor-mcp (typosquatting instructor). Flagged as malware by Amazon Inspector via OSV (MAL-2026-5317/5318/5320/5326). These names read like plausible MCP bridges for well-known libraries and are exactly what an AI assistant might suggest launching via uvx; none are published by the legitimate upstream projects. Treat every version as malicious.

Affected packages

EcosystemPackageAffected versions
pypiopenai-mcp
>= 0
pypilangchain-core-mcp
>= 0
pypitiktoken-mcp
>= 0
pypiinstructor-mcp
>= 0

Identifiers

MAL-2026-5317MAL-2026-5318MAL-2026-5320MAL-2026-5326PYSEC-2026-1069PYSEC-2026-1070PYSEC-2026-1072PYSEC-2026-1075CWE-506

References

Timeline

  • Published: 2026-06-08

← All advisories