feishu-docx-mcp@0.3.2
Malicious code in feishu-docx-mcp (npm)
Analysis
The preinstall hook of feishu-docx-mcp@0.3.2 runs `bun run index.js`, executing a 499KB obfuscated script at the package root (the legitimate package entry is dist/index.js). The obfuscated payload implements RC4 and AES-style encryption, injects a global function, and contains routines that validate GitHub access tokens and enumerate their scopes (repo, workflow) by sending `Authorization: token <token>` requests to a remote base URL. The install-time script makes outbound network connections during installation, consistent with credential harvesting and C2 beaconing.
- analyzed by
- Leitwacht
- first seen
- Sep 7, 2026, 09:27 AM
- analyzed
- Sep 7, 2026, 09:33 AM
Related advisories
- bmc-i18n-extract-cli@1.1.1
- bmc-translate-utils@1.1.1
- multicore-kit@1.1.5
- jwt-logger@2.1.9
- eth-query-utils@1.0.0
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.