autotel-mcp@28.0.3
Malicious code in autotel-mcp (npm)
T1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or Information
Analysis
This version is part of a supply-chain compromise of the autotel publisher pipeline. The package ships a ~4.5MB index.js containing a ROT13/ROT-cipher eval decoder that injects and executes a hidden payload on module import (require-time), with no install hook needed — code injection runs on every import. The affected releases were later deprecated with the note "SECURITY: compromised supply-chain build."
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 07:15 PM
- analyzed
- Jun 7, 2026, 07:26 PM
- weekly installs
- 2,043
Related advisories
- autotel-mcp@0.1.14 same package
- autotel-mcp@3.0.1 same package
- autotel-mcp@5.0.1 same package
- autotel-mcp@8.0.1 same package
- autotel-mcp@29.0.1 same package
- sensivity@2.5.39
- chai-chain-test@1.3.5
- electron-device-id@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.