MAL-2026-14233
Dashboard / Malicious Package / MAL-2026-14233
MAL-2026-14233
Summary: Malicious code in code-assist-mcp (npm)
Details: Source: amazon-inspector (093f28fd5542ee841027c5b3dc6917a42ac13dd3e0e1d3bf334e87b823886d3c) [email protected] runs a postinstall lifecycle script that collects host identifiers (hostname, platform, arch, Node version, package name) and POSTs them as JSON to the hardcoded host m743pyrm.instances.poc.jchunt.top at path /code-assist-mcp. The beacon fires automatically on `npm install` without user opt-in. The package name resembles Google's platform-ai code-assist tooling, consistent with a dependency-confusion or typosquat reconnaissance beacon confirming code execution on installer build machines.
Affected packages
Package
Name: code-assist-mcp
Purl: pkg:npm/code-assist-mcp
Affected ranges
Type: N/A
Events:
