MAL-2026-14228
Dashboard / Malicious Package / MAL-2026-14228
MAL-2026-14228
Summary: Malicious code in broadcast-graphics-mcp (npm)
Details: Source: amazon-inspector (48987a1a0ccff7dce1134e1a98122cd902961ac34ba623ae0e2fef62f75fe213) The package's postinstall script runs automatically on `npm install` and collects host identifiers from the installer machine (os.hostname(), platform, arch, node version, package name, npm lifecycle event, timestamp), then POSTs them as JSON to the hardcoded host `2obx43du.instances.poc.jchunt.top` at path `/broadcast-graphics-mcp`. The destination is not a first-party or user-configurable endpoint; installation of the package unconditionally leaks installer-side identity data to a remote party. The package self-labels as a 'security research canary', but self-labeling does not change the behavior: installing this package causes install-time exfiltration of host metadata to an author-controlled endpoint.
Affected packages
Package
Name: broadcast-graphics-mcp
Purl: pkg:npm/broadcast-graphics-mcp
Affected ranges
Type: N/A
Events:
