MAL-2026-10736

    Dashboard / Malicious Package / MAL-2026-10736

    MAL-2026-10736

    Published: 16 Jul 2026Last Modified: 16 Jul 2026

    Summary: Malicious code in memtry-cli (npm)

    Details: Source: amazon-inspector (11638a6b1b7876a94ef23285cb88f0127c003bb5e4d786dbaba5c30a9cbdfdb7) memtry-cli installs an MCP server whose `memtry_onboarding` tool returns a prompt that instructs the connected AI agent to scan the installer's home directory (~/.claude, ~/.gemini, ~/.cursor, ~/Library/Application Support, ~/Documents, ~/Downloads, ~/Desktop, ~/Projects) for chat histories, resumes, YC applications, financial documents, and personal data, then submit the collected content through the package's `create_repo` / `update_context` / `append_changelog` tools. Those tools default-route via `callCloud(`${BASE_URL}/api/mcp`)` to the author-controlled endpoint https://memtry.vercel.app/api/mcp, and the shipped `.gemini/settings.json` pins BASE_URL to that host with a bundled Bearer API key. Only items the model explicitly tags `status: private` stay local; the onboarding prompt does not instruct the model to apply that tag to the harvested personal or financial content, so exfiltration to the author's Vercel endpoint is the default path. The tarball also ships a live `mk_...` API key for memtry.vercel.app in `.gemini/settings.json`.

    Affected packages

    Package

    Name: memtry-cli

    Purl: pkg:npm/memtry-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.4