{"id":"MAL-2026-11198","summary":"Malicious code in mcp-search-server (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (03f5e3f7f8e637ac814a5040b2e61c8608327f73b1c44352e694848a8c35e181)\nOn import, server.py starts a background thread that issues an HTTP GET to the hardcoded bare-IP endpoint http://187.127.73.142:8777 carrying a per-host identifier derived from os.uname().nodename hashed with the current time (SWARM_ID). The beacon fires unconditionally under _swarm_connect(), labelled in comments as 'Silent background connection' / 'Auto-connect on import (silent)'. Separately, the advertised web_search and image_search tools route all caller-supplied query text over cleartext HTTP to the same hardcoded bare IP (http://187.127.73.142:8080/search), presented as an 'uncensored SearXNG' instance, with no configuration option to redirect to a different backend. The README frames the beacon as an 'optional distributed compute swarm', but the code contains no opt-in flag and runs the connection on every import. The result is a hardcoded, unconfigurable relay of both host identity and user search queries to an author-controlled bare IP over plain HTTP.\n\n## Source: kam193 (75c59285ee1a5a83447815e7402410ccfca6a287e0c36d61bcfda3d55396f608)\nVersions published in 2026-07 (after the package was removed by the original author and the name was re-registered by another) contain a stub 'share compute swarm' functionality for 'faster results'. The functionality was not fully implemented - the package only reports home on every run - but the other package, published at the same time by the same user, advertised boosting AI, but in fact started coinmining. The wording around 'swarm' changed over releases: originally advertised as an explicit optional feature, was then moved in code as a silent, forced phoning home. Given the other package published simultaneously, it is quite sure the package was preparing to deploy coin miners on user's machine.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-mcp-search-server\n\n\nReasons (based on the campaign):\n\n\n - other\n","modified":"2026-08-04T23:05:47.146060487Z","published":"2026-07-30T17:30:32Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-30T17:33:32.596269Z","sha256":"668e6c74d0665065f6c75fb03d82071cda10cea3ad8f1cd20068cbe2c702d728","source":"kam193","versions":["1.0.0","2.0.0","2.0.1"],"id":"pypi/2026-07-mcp-search-server/mcp-search-server","import_time":"2026-07-30T18:02:01.370894824Z"},{"id":"pypi/2026-07-mcp-search-server/mcp-search-server","import_time":"2026-07-30T21:30:36.849265952Z","modified_time":"2026-07-30T17:33:32.596269Z","sha256":"75c59285ee1a5a83447815e7402410ccfca6a287e0c36d61bcfda3d55396f608","source":"kam193","versions":["1.0.0","2.0.0","2.0.1"]},{"sha256":"abc86f89945197c8cfbe8d05fbc6a1b4ad62950800c7b3a83c7fe317e330b334","source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-011223","import_time":"2026-08-04T22:30:05.914384026Z","modified_time":"2026-08-04T21:50:08Z"},{"modified_time":"2026-08-04T21:49:49Z","sha256":"03f5e3f7f8e637ac814a5040b2e61c8608327f73b1c44352e694848a8c35e181","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-011221","import_time":"2026-08-04T22:30:05.812458371Z"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-011273","import_time":"2026-08-04T22:30:08.404487907Z","modified_time":"2026-08-04T21:57:35Z","sha256":"5e1fc6ecdee1eb65dd43b732ab380cfc31ba7e9bcf7af3057222fc9c2e5ccccc"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/campaign/2026-07-mcp-search-server"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp-search-server/2.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp-search-server/2.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/mcp-search-server/1.0.0/"}],"affected":[{"package":{"name":"mcp-search-server","ecosystem":"PyPI","purl":"pkg:pypi/mcp-search-server"},"versions":["1.0.0","2.0.0","2.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"server.py","sha256":"15f31d27d0f3b8fa539d533c7537d38a962f0de8c89b6336710527ea30109af4","tlsh":"82917452fc56682396faa5586478e1c2777d664761046c7cfdec8a380f4ccb354b8298"}],"package_integrity":[{"filename":"mcp_search_server-2.0.0-py3-none-any.whl","hashes":{"blake2b_256":"df2158a6364e19d22c4e34fbff33b41c9463acc16dcb751bf5205cb5598589a5","md5":"17b519831940bbf76d6f6fa001acda90","sha256":"dc2f6cc8694e60135d3a9fe047e2d767909e5ac93efeb3b4cd3600bb7d965903"}},{"filename":"mcp_search_server-2.0.0.tar.gz","hashes":{"sha256":"9b70ab1f5a98a658e0002b879c2b8de894045ba72ff60eb914c061a989a1f1b3","blake2b_256":"414d932d959b961d02b8e5c6b4586a7ae0a1b52aa9e3a06556ffbfcc23fb6966","md5":"c368a8a5592eb4b980ef07221772fb16"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/mcp-search-server/MAL-2026-11198.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}