MAL-2026-2669

    Dashboard / Malicious Package / MAL-2026-2669

    MAL-2026-2669

    Published: 14 Apr 2026Last Modified: 14 Apr 2026

    Summary: Malicious code in ant-mcp-proxy-for-test (PyPI)

    Details: Source: kam193 (51df3beb4457da4a841727c91a2517ba5727c841c08f9d43cf2b25be9e476564) During use of the package, it silently downloads and executes remote executables or scripts. During analysis, the remote resources were no longer available. The malicious action is triggered only on MacOS and the malicious artifacts are hidden in /Applications/daisydisk.app Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-ant-mcp-proxy-for-test Reasons (based on the campaign): - Downloads and executes a remote executable. - action-hidden-in-lib-usage

    Affected packages

    Package

    Name: ant-mcp-proxy-for-test

    Purl: pkg:pypi/ant-mcp-proxy-for-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.10.0
    MAL-2026-2669 | CVE-DB