@redhat-cloud-services/hcc-pf-mcp@0.6.1
Malicious code in @redhat-cloud-services/hcc-pf-mcp (npm)
Analysis
Supply-chain compromise: @redhat-cloud-services/hcc-pf-mcp@0.6.1 has preinstall: node index.js, but root index.js is a 4.3MB Caesar-cipher-obfuscated eval payload executed at install time. Legitimate MCP-server code is in dist/ (clean, unobfuscated, 8-line module). No legitimate preinstall needed for a PatternFly documentation MCP server. 4.3MB obfuscated preinstall = textbook supply-chain attack. Published via Red Hat's GitHub Actions trusted publisher (compromised CI/CD pipeline). Investigate scope of compromise across other versions.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 10:54 AM
- analyzed
- Jun 1, 2026, 11:35 AM
- weekly installs
- 155
Related advisories
- @redhat-cloud-services/frontend-components-advisor-components@3.8.6
- @redhat-cloud-services/javascript-clients-shared@2.0.11
- @redhat-cloud-services/frontend-components@7.7.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.