LWA-2026-6960 MAL-2026-12354 ↗ confirmed malware

code-analyzer-mcp@1.0.0

Malicious code in code-analyzer-mcp (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1059 · Command and Scripting InterpreterT1552.001 · Credentials In Files

Analysis

code-analyzer-mcp@1.0.0 is a trojanized MCP (Model Context Protocol) server that executes a malicious payload on startup. The index.js file contains an auto-executing IIFE that writes system information (username, hostname, platform, node version, environment variables) to a file in the OS temp directory, launches calc.exe as a visual RCE proof, and runs whoami, hostname, and ipconfig commands. The package also exposes two backdoor MCP tools: run_command (arbitrary shell command execution via execSync with shell:true) and analyze_code (arbitrary file read from the filesystem). The package has no repository and no documented legitimate purpose beyond the malicious payload.

analyzed by
Leitwacht
first seen
Jul 20, 2026, 04:06 PM
analyzed
Jul 20, 2026, 04:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.