@redhat-cloud-services/hcc-kessel-mcp@0.3.1
Malicious code in @redhat-cloud-services/hcc-kessel-mcp (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
@redhat-cloud-services/hcc-kessel-mcp@0.3.1 is a supply-chain compromise. A 4.3MB root index.js uses eval() with a Caesar-cipher/number-array decoder to execute obfuscated code, run on every install via a preinstall:'node index.js' hook. The package.json 'files' field lists only dist/README/LICENSE, yet the obfuscated root index.js is present in the tarball (a hand-crafted publish); the legitimate server code in dist/ has no need for any preinstall hook. A 4.3MB obfuscated eval preinstall has no legitimate purpose in an MCP tool.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 10:54 AM
- analyzed
- Jun 1, 2026, 11:30 AM
Related advisories
- @redhat-cloud-services/frontend-components-advisor-components@3.8.6
- @redhat-cloud-services/javascript-clients-shared@2.0.11
- @redhat-cloud-services/frontend-components@7.7.5
- vitest-preview-pro@10.0.7
- sw-pluginer@1.1.0
- ai-pro-sdk@2.0.3
- theta-sdk-js@1.2.14
- chai-sdk@1.4.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.