LWA-2026-2173 MAL-2026-5140 ↗ confirmed malware

@redhat-cloud-services/hcc-pf-mcp@0.6.1

Malicious code in @redhat-cloud-services/hcc-pf-mcp (npm)

Analysis

Supply-chain compromise: @redhat-cloud-services/hcc-pf-mcp@0.6.1 has preinstall: node index.js, but root index.js is a 4.3MB Caesar-cipher-obfuscated eval payload executed at install time. Legitimate MCP-server code is in dist/ (clean, unobfuscated, 8-line module). No legitimate preinstall needed for a PatternFly documentation MCP server. 4.3MB obfuscated preinstall = textbook supply-chain attack. Published via Red Hat's GitHub Actions trusted publisher (compromised CI/CD pipeline). Investigate scope of compromise across other versions.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 10:54 AM
analyzed
Jun 1, 2026, 11:35 AM
weekly installs
155

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.