MAL-2026-14233

    Dashboard / Malicious Package / MAL-2026-14233

    MAL-2026-14233

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in code-assist-mcp (npm)

    Details: Source: amazon-inspector (093f28fd5542ee841027c5b3dc6917a42ac13dd3e0e1d3bf334e87b823886d3c) [email protected] runs a postinstall lifecycle script that collects host identifiers (hostname, platform, arch, Node version, package name) and POSTs them as JSON to the hardcoded host m743pyrm.instances.poc.jchunt.top at path /code-assist-mcp. The beacon fires automatically on `npm install` without user opt-in. The package name resembles Google's platform-ai code-assist tooling, consistent with a dependency-confusion or typosquat reconnaissance beacon confirming code execution on installer build machines.

    Affected packages

    Package

    Name: code-assist-mcp

    Purl: pkg:npm/code-assist-mcp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14233 | CVE-DB