{"id":"MAL-2026-10541","summary":"Malicious code in proxy-seller-mcp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ae92b460e6db9195467e69567fadc3286877ea8e6b121448288a4f77acf5201)\nPackage is published as `proxy-seller-mcp` with `author: \"Proxy-Seller\"` in package.json and a README directing users to obtain an API key at https://front-v2.proxy-seller.com — the legitimate Proxy-Seller domain. However, the hardcoded default API base URL in dist/config.js line 13 is `https://the assessment.bydloss.mom`, an unrelated domain, and dist/stdio.js line 7 instructs users to fetch their API key from `https://the assessment.bydloss.mom/personal/api`. Every MCP tool invocation sends the caller's Proxy-Seller API key (embedded in the URL path) along with proxy-management operations (orders, balance top-ups, credential retrieval, list/replace/delete) to bydloss.mom rather than to Proxy-Seller. The repository field points at a personal GitHub account (`dmitriyn3679/mcp`), not a Proxy-Seller organization. The combination of vendor-name impersonation in package metadata, README pointing to the legitimate vendor, and code defaulting to an unrelated domain is deliberate misdirection — any developer who installs and configures this MCP will hand over live Proxy-Seller credentials and proxy-account control to the operator of bydloss.mom on first tool use.\n","modified":"2026-07-14T04:46:57.833402553Z","published":"2026-07-14T03:47:41Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["0.1.7"],"id":"IN-MAL-2026-010380","import_time":"2026-07-14T04:32:00.001056239Z","modified_time":"2026-07-14T03:47:41Z","sha256":"6ae92b460e6db9195467e69567fadc3286877ea8e6b121448288a4f77acf5201"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/proxy-seller-mcp/v/0.1.7"}],"affected":[{"package":{"name":"proxy-seller-mcp","ecosystem":"npm","purl":"pkg:npm/proxy-seller-mcp"},"versions":["0.1.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"proxy-seller-mcp-0.1.7.tgz","hashes":{"sha512_sri":"sha512-ZA+4ev697oa858arEZ99J9HuwS04dMZJh7xEn40aVCXqFlJVeyHQw4a03BCx46rmC2mJLxxPj+AhqKik1d2Dug==","sha1":"3b4ed46e9d9840c85b1538e4eca6601b9cd14a1e"}}],"evidence_files":[{"tlsh":"1f011548d5bb28aa06325f94047f9323f6bc3003390591dc736cb2183f5193d42f3969","path":"dist/config.js","sha256":"59c4a474674f1380fae046ba1b3bf6d8c84bdddf45445ca9b9c8e72ec6edfd45"},{"path":"package.json","sha256":"47bef941a1e08055a27bec6276fb3b02cfe9036475560b61cc423d4437ef7e24","tlsh":"4731a929cab65c7747cd56c0a86a2182b72884478d18fd0933d6412c4f9d06f96ff2ec"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/proxy-seller-mcp/MAL-2026-10541.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}