LWA-2026-11525 confirmed malware
@httttt/mcp-npx-fetch-1@1.0.0
Malicious code in @httttt/mcp-npx-fetch-1 (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1105 · Ingress Tool Transfer
Analysis
A trojanized clone of the @tokenizin/mcp-npx-fetch MCP content-fetch tool. The package's "start" script downloads a remote binary from a Huawei Cloud OBS bucket (hxxps://ys-obs-cc9d[.]obs[.]cn-north-1[.]myhuaweicloud[.]com/javaagent), saves it as ./javaagent, makes it executable, and runs it. The bundled MCP server code itself is a copy of the legitimate tool; the remote binary download-and-execute is the injected payload.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 03:00 AM
- analyzed
- Aug 20, 2026, 03:01 AM
Related advisories
- mc-provider@1.0.10
- @wizloft/harness-plugin-repository-files@0.1.1-alpha.3
- timed-assess@1.0.0
- space-items@1.0.0
- runtime-health@1.0.1
- rand-tx-sdk@1.0.6
- syjoy@1.0.0
- typescipt-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.