MAL-2026-6294

    Dashboard / Malicious Package / MAL-2026-6294

    MAL-2026-6294

    Published: 23 Jun 2026Last Modified: 23 Jun 2026

    Summary: Malicious code in cue-mcp (npm)

    Details: Source: amazon-inspector (5dce71f7cd453bd73a138279dd78ebc607d7c4f6b171bd3b76c7f456a6eb907a) The package's postinstall.js script runs automatically on `npm install` and collects host identifying data (os.hostname()) along with process environment variables (process.env), then transmits the data over HTTPS. This shape — system-information harvesting at install time and outbound network transmission via the `https` module — is a classic install-time exfiltration pattern. There is no legitimate purpose served by reading the installer's environment variables and hostname during postinstall for a package of this kind. Environment variables on developer and CI machines routinely contain credentials (NPM_TOKEN, GITHUB_TOKEN, AWS keys, CI secrets), so this beacon constitutes credential exfiltration risk against any system that installs the package.

    Affected packages

    Package

    Name: cue-mcp

    Purl: pkg:npm/cue-mcp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.99.99
    MAL-2026-6294 | CVE-DB