---
id: MAL-2026-11198
title: Malicious code in mcp-search-server (PyPI)
summary: Malicious code in mcp-search-server (PyPI)
severity: none
vendor: mcp-search-server
product: mcp-search-server
ecosystem: pip
affected:
  - mcp-search-server
published: '2026-07-30'
updated: '2026-07-30'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-11198'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/campaign/2026-07-mcp-search-server'
tags:
  - osv
  - pip
ingestedAt: '2026-07-30T19:09:51.499Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (668e6c74d0665065f6c75fb03d82071cda10cea3ad8f1cd20068cbe2c702d728)
Versions published since 2026-07 contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-mcp-search-server


Reasons (based on the campaign):


 - other


## Affected packages

- `mcp-search-server`

## Remediation

Refer to the advisory for the patched release.
