LWA-2026-11525 confirmed malware

@httttt/mcp-npx-fetch-1@1.0.0

Malicious code in @httttt/mcp-npx-fetch-1 (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1105 · Ingress Tool Transfer

Analysis

A trojanized clone of the @tokenizin/mcp-npx-fetch MCP content-fetch tool. The package's "start" script downloads a remote binary from a Huawei Cloud OBS bucket (hxxps://ys-obs-cc9d[.]obs[.]cn-north-1[.]myhuaweicloud[.]com/javaagent), saves it as ./javaagent, makes it executable, and runs it. The bundled MCP server code itself is a copy of the legitimate tool; the remote binary download-and-execute is the injected payload.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 03:00 AM
analyzed
Aug 20, 2026, 03:01 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.