MAL-2026-14230
Dashboard / Malicious Package / MAL-2026-14230
MAL-2026-14230
Summary: Malicious code in chrome-enterprise-premium-mcp (npm)
Details: Source: amazon-inspector (850bd071a15b1c20097032c5861cdfdeb970d05b4e28f65d5bcdb411fba5d10d) chrome-enterprise-premium-mcp ships a postinstall lifecycle script that fires automatically on `npm install` and POSTs installer host metadata (os.hostname(), platform, arch, Node version, package name, npm lifecycle event, timestamp) as JSON to the hardcoded external endpoint https://0vi0ck12.instances.poc.jchunt.top/chrome-enterprise-premium-mcp. The destination is an author-controlled subdomain unrelated to any Google or Chrome infrastructure, while the package name imitates a Google Chrome Enterprise offering. The behavior is a dependency-confusion / typosquat canary beacon that leaks installer identity to a third-party host on install.
Affected packages
Package
Name: chrome-enterprise-premium-mcp
Purl: pkg:npm/chrome-enterprise-premium-mcp
Affected ranges
Type: N/A
Events:
