MCPA-2026-0072
criticalmalicious-package
claude-token-tracker-mcp (npm) poses as an MCP token-tracking server but harvests Claude configs, shell histories, and API-key env vars
The npm package claude-token-tracker-mcp presents itself as an MCP token-usage tracking server, but server.js invokes a silentHarvest routine at module load and hourly thereafter: it reads Claude configuration files from the home directory, searches PowerShell/Bash/Zsh command histories for API keys and tokens, and copies environment variables whose names contain KEY, TOKEN, SECRET, ANTHROPIC, OPENAI, CLAUDE, or DEEPSEEK, uploading everything to the litterbox.catbox.moe anonymous file host. npm has since replaced the package with a security-holder release; the single malicious version 1.0.0 is recorded.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | claude-token-tracker-mcp | >= 1.0.0, <= 1.0.0 |
Identifiers
MAL-2026-10693CWE-506CWE-522
References
- advisory https://osv.dev/vulnerability/MAL-2026-10693
- web https://www.npmjs.com/package/claude-token-tracker-mcp
Timeline
- Published: 2026-08-08