MAL-2026-14228

    Dashboard / Malicious Package / MAL-2026-14228

    MAL-2026-14228

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in broadcast-graphics-mcp (npm)

    Details: Source: amazon-inspector (48987a1a0ccff7dce1134e1a98122cd902961ac34ba623ae0e2fef62f75fe213) The package's postinstall script runs automatically on `npm install` and collects host identifiers from the installer machine (os.hostname(), platform, arch, node version, package name, npm lifecycle event, timestamp), then POSTs them as JSON to the hardcoded host `2obx43du.instances.poc.jchunt.top` at path `/broadcast-graphics-mcp`. The destination is not a first-party or user-configurable endpoint; installation of the package unconditionally leaks installer-side identity data to a remote party. The package self-labels as a 'security research canary', but self-labeling does not change the behavior: installing this package causes install-time exfiltration of host metadata to an author-controlled endpoint.

    Affected packages

    Package

    Name: broadcast-graphics-mcp

    Purl: pkg:npm/broadcast-graphics-mcp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14228 | CVE-DB