MCPA-2026-0067
criticalmalicious-package
brave-search-mcp-server (npm) — malicious squat of the official Brave Search MCP server name
The unscoped npm package brave-search-mcp-server 1.0.0 squats the name of the official Brave Search MCP server (published as @brave/brave-search-mcp-server). OpenSSF Package Analysis flagged the package as malicious: it communicates with a domain associated with malicious activity and executes commands associated with malicious behavior. MCP client configs commonly launch search servers via `npx <name>`, and the unscoped name is the obvious guess for Brave's server, so a config referencing the unscoped name executed the payload. npm has removed the package (replaced with a 0.0.1-security placeholder); every real version is recorded as affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | brave-search-mcp-server | >= 0 |
Identifiers
GHSA-56pv-xqqh-57cfMAL-2026-5182CWE-506
References
- advisory https://github.com/advisories/GHSA-56pv-xqqh-57cf
- advisory https://osv.dev/vulnerability/MAL-2026-5182
Timeline
- Published: 2026-07-27