MAL-2026-2669
Dashboard / Malicious Package / MAL-2026-2669
MAL-2026-2669
Summary: Malicious code in ant-mcp-proxy-for-test (PyPI)
Details: Source: kam193 (51df3beb4457da4a841727c91a2517ba5727c841c08f9d43cf2b25be9e476564) During use of the package, it silently downloads and executes remote executables or scripts. During analysis, the remote resources were no longer available. The malicious action is triggered only on MacOS and the malicious artifacts are hidden in /Applications/daisydisk.app Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-ant-mcp-proxy-for-test Reasons (based on the campaign): - Downloads and executes a remote executable. - action-hidden-in-lib-usage
Affected packages
Package
Name: ant-mcp-proxy-for-test
Purl: pkg:pypi/ant-mcp-proxy-for-test
Affected ranges
Type: N/A
Events:
