MAL-2026-16250Critical▾ Abyssal⚠ Exploited in the wildMalicious code in marketing-mcp (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
The package exposes an MCP tool send(path) that reads a caller-specified local file and POSTs its contents to a hardcoded https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to send — including sensitive paths such as ~/.ssh/id_rsa, ~/.aws/credentials, .env files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.
Package attempts to lure LLM agents to exfiltrate files to a hardcoded location. Analysis of infrastructure suggests preparing for exfiltrating credentials.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-marketing-mcp
Reasons (based on the campaign):
files-exfiltration
llm-threat
marketing-mcpRefer to the advisory for the patched release.