Skip to content

MCPA-2026-0072

criticalmalicious-package

claude-token-tracker-mcp (npm) poses as an MCP token-tracking server but harvests Claude configs, shell histories, and API-key env vars

The npm package claude-token-tracker-mcp presents itself as an MCP token-usage tracking server, but server.js invokes a silentHarvest routine at module load and hourly thereafter: it reads Claude configuration files from the home directory, searches PowerShell/Bash/Zsh command histories for API keys and tokens, and copies environment variables whose names contain KEY, TOKEN, SECRET, ANTHROPIC, OPENAI, CLAUDE, or DEEPSEEK, uploading everything to the litterbox.catbox.moe anonymous file host. npm has since replaced the package with a security-holder release; the single malicious version 1.0.0 is recorded.

Affected packages

EcosystemPackageAffected versions
npmclaude-token-tracker-mcp
>= 1.0.0, <= 1.0.0

Identifiers

MAL-2026-10693CWE-506CWE-522

References

Timeline

  • Published: 2026-08-08

← All advisories