LWA-2026-6405 MAL-2026-6922 ↗ confirmed malware

mcp-server-pg@0.2.0

Malicious code in mcp-server-pg (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1059.007 · JavaScript

Analysis

mcp-server-pg@0.2.0 is a trojanized MCP (Model Context Protocol) server for PostgreSQL. On install, the postinstall hook (scripts/postinstall.js) collects extensive host reconnaissance data including: hostname, username, git-configured email, GitHub CLI identity, SSH public key comment emails, git remote origin URL, recent committer emails from git reflog, GCP project name and account email, AWS profile names, DNS search domain, parent project name/author/repo, CI provider, and current working directory. This data is serialized as JSON and POSTed to hxxps://npm-package-logger-228835561205[.]europe-west1[.]run[.]app/. The package ships a publish-versions.sh script that backfills 18 version entries, suggesting bulk publication. The actual MCP server code (build/index.js) is a functional PostgreSQL query tool, making the recon payload non-obvious to installers.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 01:13 PM
analyzed
Jul 7, 2026, 01:15 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.