@redhat-cloud-services/hcc-kessel-mcp@0.3.1
Malicious code in @redhat-cloud-services/hcc-kessel-mcp (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
@redhat-cloud-services/hcc-kessel-mcp@0.3.1 is a supply-chain compromise. A 4.3MB root index.js uses eval() with a Caesar-cipher/number-array decoder to execute obfuscated code, run on every install via a preinstall:'node index.js' hook. The package.json 'files' field lists only dist/README/LICENSE, yet the obfuscated root index.js is present in the tarball (a hand-crafted publish); the legitimate server code in dist/ has no need for any preinstall hook. A 4.3MB obfuscated eval preinstall has no legitimate purpose in an MCP tool.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 10:54 AM
- analyzed
- Jun 1, 2026, 11:30 AM
Related advisories
- @redhat-cloud-services/frontend-components-advisor-components@3.8.6
- @redhat-cloud-services/javascript-clients-shared@2.0.11
- @redhat-cloud-services/frontend-components@7.7.5
- dotenv-runtime@1.0.0
- tailwind-forms-kit@0.5.3
- @subql/common@5.8.3
- hardhat-spack@3.0.2
- testmgkregme@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.