Skip to content

MCPA-2026-0061

criticalmalicious-package

opencode-optimised-toolings (npm) replaces the OpenCode binary with a build from a non-publisher repository

The npm package opencode-optimised-toolings poses as an OpenCode plugin. On plugin load it runs a self-patch pipeline without user prompt: it downloads an OpenCode source tarball from a non-publisher GitHub repository (github.com/anomalyco/opencode, distinct from upstream sst/opencode), builds it, renames the user's on-PATH opencode executable aside, and installs the newly built binary in its place — every subsequent `opencode` invocation on the host runs attacker-built code. GHSA flags versions 3.4.0/4.0.0/4.0.1; the package remained live on npm afterward, and the 6.2.0 tarball verified on 2026-08-03 still contains the same self-patch pipeline downloading from the same non-publisher repository, so every version is recorded as affected.

Affected packages

EcosystemPackageAffected versions
npmopencode-optimised-toolings
>= 0

Identifiers

GHSA-49cx-27xq-h4g2MAL-2026-13452CWE-506

References

Timeline

  • Published: 2026-08-07

← All advisories