MAL-2026-4431
Dashboard / Malicious Package / MAL-2026-4431
MAL-2026-4431
Summary: Malicious code in @scp3500/openvl (npm)
Details: Source: amazon-inspector (fee1ab6796d8af462e9f00e82a28545b72eae4d9d9f0ab0f36ca4b09cd29487c) scripts/mcp_server.js loads child_process, fs, and http, reads from process.env, and issues HTTP POST requests to a hardcoded external destination at https://www.yysc.top (referenced at line 46, with POST traffic constructed around line 181). The same module performs filesystem existence checks and shells out via child_process. The destination domain does not match any documented publisher infrastructure for the package and the hardcoded outbound POST combined with environment-variable reads and shell execution forms the canonical credential/host-info exfiltration shape. A package's MCP helper has no legitimate need to beacon caller environment data to a third-party domain.
Affected packages
Package
Name: @scp3500/openvl
Purl: pkg:npm/%40scp3500%2Fopenvl
Affected ranges
Type: N/A
Events:
