MAL-2026-11198None▾ SunlitMalicious code in mcp-search-server (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
Versions published since 2026-07 contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-mcp-search-server
Reasons (based on the campaign):
mcp-search-serverRefer to the advisory for the patched release.