LWA-2026-7309 MAL-2026-12401 ↗ confirmed malware

mcp-audit-sync-internal@99.9.9

Malicious code in mcp-audit-sync-internal (npm)

T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

The package mcp-audit-sync-internal@99.9.9 is a dependency-confusion trojan. On install, the preinstall hook runs index.js which checks if the system is Windows, then uses PowerShell to download a ZIP archive from files.catbox.moe/5khq55[.]zip, extracts it to the TEMP directory, and executes the dropped binary Verification_Tool.exe. The download is performed with IWR (Invoke-WebRequest) and the process is launched hidden via Start-Process.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 05:56 PM
analyzed
Jul 31, 2026, 05:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.