MCPA-2026-0061
opencode-optimised-toolings (npm) replaces the OpenCode binary with a build from a non-publisher repository
The npm package opencode-optimised-toolings poses as an OpenCode plugin. On plugin load it runs a self-patch pipeline without user prompt: it downloads an OpenCode source tarball from a non-publisher GitHub repository (github.com/anomalyco/opencode, distinct from upstream sst/opencode), builds it, renames the user's on-PATH opencode executable aside, and installs the newly built binary in its place — every subsequent `opencode` invocation on the host runs attacker-built code. GHSA flags versions 3.4.0/4.0.0/4.0.1; the package remained live on npm afterward, and the 6.2.0 tarball verified on 2026-08-03 still contains the same self-patch pipeline downloading from the same non-publisher repository, so every version is recorded as affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | opencode-optimised-toolings | >= 0 |
Identifiers
GHSA-49cx-27xq-h4g2MAL-2026-13452CWE-506
References
- advisory https://github.com/advisories/GHSA-49cx-27xq-h4g2
- advisory https://osv.dev/vulnerability/MAL-2026-13452
Timeline
- Published: 2026-08-07