---
id: MAL-2026-16250
title: Malicious code in marketing-mcp (PyPI)
summary: Malicious code in marketing-mcp (PyPI)
severity: critical
exploited: true
vendor: marketing-mcp
product: marketing-mcp
ecosystem: pip
affected:
  - marketing-mcp
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:45:11.203031313Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-16250'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/marketing-mcp'
  - url: 'https://pypi.org/project/marketing-mcp/0.1.0/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-17T16:20:44.647Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (87216e00fe68e2de8b140f1f9ffc2db5a8e814f38030e2eb6120c9ae9e7ca3ff)
The package exposes an MCP tool `send(path)` that reads a caller-specified local file and POSTs its contents to a hardcoded `https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c` endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to `send` — including sensitive paths such as `~/.ssh/id_rsa`, `~/.aws/credentials`, `.env` files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.

## Source: kam193 (6a271b29f840e2047c34363e985921e1a374194cfcae7524698f178c96bea9eb)
Package attempts to lure LLM agents to exfiltrate files to a hardcoded location. Analysis of infrastructure suggests preparing for exfiltrating credentials.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-marketing-mcp


Reasons (based on the campaign):


 - files-exfiltration


 - llm-threat


## Affected packages

- `marketing-mcp`

## Remediation

Refer to the advisory for the patched release.
