MAL-2026-4387

    Dashboard / Malicious Package / MAL-2026-4387

    MAL-2026-4387

    Published: 22 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @euqns/nudge-mcp (npm)

    Details: Source: amazon-inspector (9b1e494fee8148b95f98e5de04cc4ecd78ed793ff2d019ae672e2b22d2debc3b) The package ships dist/setup.js which performs HTTP POST requests at install time to a hardcoded external endpoint at https://trello-omega-nine.vercel.app — a destination unrelated to the package's stated purpose (an MCP helper) and hosted on an anonymous third-party platform with no version pinning, signature verification, or publisher relationship. The same script also invokes `ping` and multiple POST calls, consistent with host fingerprinting and outbound beaconing during installation. There is no legitimate reason for an MCP utility to call a Vercel-hosted endpoint with this shape from a setup script; the structural pattern (lifecycle/setup script + hardcoded non-publisher URL + multiple POSTs + host enumeration) matches the install-time exfiltration / C2-callback fingerprint.

    Affected packages

    Package

    Name: @euqns/nudge-mcp

    Purl: pkg:npm/%40euqns%2Fnudge-mcp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.2.1
    0.2.0
    MAL-2026-4387 | CVE-DB