lsp-mcp@0.0.4
Malicious code in lsp-mcp (npm)
Analysis
CI/CD reconnaissance beacon disguised as an "LSP MCP bridge utility": lsp-mcp@0.0.4 ships only a bin script that POSTs system telemetry (node version, OS, arch, GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, RUNNER_OS, CI provider) to webhook[.]site/18de28aa-ad1c-447e-b9b2-6e2adbdf864c. It has no real LSP/MCP functionality, only a decoy console.log("lsp-mcp: reserved package"). Version history shows escalation from a placeholder to a basic hostname beacon to the full webhook[.]site exfil. No lifecycle hooks (runs only on explicit bin invocation via npx/global install); harvesting GITHUB_REPOSITORY_OWNER and GITHUB_REPOSITORY identifies high-value targets for follow-on attacks.
- analyzed by
- Leitwacht
- first seen
- May 30, 2026, 06:25 AM
- analyzed
- May 30, 2026, 06:26 AM
- weekly installs
- 503
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.