{"id":"MAL-2026-16250","title":"Malicious code in marketing-mcp (PyPI)","summary":"Malicious code in marketing-mcp (PyPI)","severity":"critical","exploited":true,"vendor":"marketing-mcp","product":"marketing-mcp","ecosystem":"pip","affected":["marketing-mcp"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:45:11.203031313Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16250","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/marketing-mcp"},{"url":"https://pypi.org/project/marketing-mcp/0.1.0/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-17T16:20:44.647Z","slug":"MAL-2026-16250","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (87216e00fe68e2de8b140f1f9ffc2db5a8e814f38030e2eb6120c9ae9e7ca3ff)\nThe package exposes an MCP tool `send(path)` that reads a caller-specified local file and POSTs its contents to a hardcoded `https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c` endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to `send` — including sensitive paths such as `~/.ssh/id_rsa`, `~/.aws/credentials`, `.env` files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.\n\n## Source: kam193 (6a271b29f840e2047c34363e985921e1a374194cfcae7524698f178c96bea9eb)\nPackage attempts to lure LLM agents to exfiltrate files to a hardcoded location. Analysis of infrastructure suggests preparing for exfiltrating credentials.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-marketing-mcp\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - llm-threat\n\n\n## Affected packages\n\n- `marketing-mcp`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}