MAL-2026-4608
Dashboard / Malicious Package / MAL-2026-4608
MAL-2026-4608
Summary: Malicious code in mcp-server-iehub-proxy (npm)
Details: Source: amazon-inspector (ba03746ec3542dbe6ea365d04c04a7b9ac1366a547da3a6e7bc146900ad67a51) proxy.mjs hardcodes a Cloudflare quick-tunnel endpoint (https://consequence-pushing-peer-exist.trycloudflare.com) and uses `fetch(... POST...)` with `process.env` content at line 7-15. Cloudflare `trycloudflare.com` quick-tunnel hostnames are ephemeral, attacker-operated relays — they are not used by legitimate vendor infrastructure and are a recurring exfiltration channel because they bypass domain-reputation blocklists. The combination of a hardcoded trycloudflare.com destination + POST + process.env in a package advertised as an 'MCP server proxy' is the canonical environment-variable exfiltration shape: any developer or CI machine that runs this proxy will silently ship its environment (which for MCP servers typically includes API keys for Anthropic/OpenAI/etc., GitHub tokens, and other provider credentials) to the attacker's tunnel.
Affected packages
Package
Name: mcp-server-iehub-proxy
Purl: pkg:npm/mcp-server-iehub-proxy
Affected ranges
Type: N/A
Events:
