{"id":"MAL-2026-4775","summary":"Malicious code in wdt-erpmcp (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ec852c69947e2a2575ae37ce4a442a67dc01f7328c0c603b94c87aa84803623f)\nwdt-erpmcp advertises itself as a generic MCP wrapper over the caller's Wangdian Tongda (WDT) ERP, and three of its four tools correctly read WDT_APPKEY / WDT_APPSECRET / WDT_SID from the environment. The fourth tool, erp_purchase_order_push, deviates from that pattern: in wdt_erpmcp/erp_service.py lines 79-83, it instantiates `WdtClient('ruoxi2-otc', 'e3c96189b699db691e48ef61070e151f', 'ruoxi2', 'https://api.wangdian.cn/openapi2/')` with hardcoded credentials. Any caller invoking this tool submits supplier, warehouse, SKU, and price data into the author-controlled `ruoxi2` WDT tenant rather than their own — the caller's purchase-order data is silently relayed to a fixed third-party account they did not configure, and the author gains the ability to observe or fabricate orders bearing caller-supplied data. The hardcoded WDT app secret is also extractable from the source, allowing any installer to call api.wangdian.cn as that tenant. The asymmetry between the three env-var-driven tools and the one hardcoded tool, together with the silent destination override, fits the silent-relay pattern.\n","modified":"2026-05-26T06:03:15.672344886Z","published":"2026-05-21T06:46:46Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-004610","import_time":"2026-05-26T05:52:56.567658321Z","modified_time":"2026-05-25T08:57:43Z","sha256":"38284b64d04b6304f62117015635391945cc6f867656311bb6d54a13a182ecf8","source":"amazon-inspector","versions":["0.1.7"]},{"source":"amazon-inspector","versions":["0.1.5"],"id":"IN-MAL-2026-003765","import_time":"2026-05-26T05:51:16.360066754Z","modified_time":"2026-05-21T06:46:46Z","sha256":"ec852c69947e2a2575ae37ce4a442a67dc01f7328c0c603b94c87aa84803623f"},{"source":"amazon-inspector","versions":["0.1.6"],"id":"IN-MAL-2026-004611","import_time":"2026-05-26T05:52:56.675642624Z","modified_time":"2026-05-25T08:57:49Z","sha256":"feefb8fb1658f7c81f142a2d83101cd03364d149842a5a2e115f3deb2d8594ce"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/wdt-erpmcp/0.1.7/"},{"type":"PACKAGE","url":"https://pypi.org/project/wdt-erpmcp/0.1.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/wdt-erpmcp/0.1.6/"}],"affected":[{"package":{"name":"wdt-erpmcp","ecosystem":"PyPI","purl":"pkg:pypi/wdt-erpmcp"},"versions":["0.1.7","0.1.5","0.1.6"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"c391012acd96d40154ff8ba6ac2c8049f62c539332741192fd3d07292f38f959a76ef9","path":"wdt_erpmcp/erp_service.py","sha256":"3aaa00a08ad096b1e312bb219d8623b8b2d98d3176d626f865076cdc92ab1303"}],"package_integrity":[{"filename":"wdt_erpmcp-0.1.7-py3-none-any.whl","hashes":{"sha256":"c0e90406918f882a5669ceab9ad64a526cc37158d518190928b8d452cef7661f","blake2b_256":"5c1a83815961e8fb58bdc9e50fe32de5b4143d3d467cbcf65877d42796dd6f08","md5":"5cbf7bafb3a708aec1021652f53d61f3"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wdt-erpmcp/MAL-2026-4775.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}