CRITICAL PyPI Malware

Malicious code in marketing-mcp (PyPI)

MAL-2026-16250

Published · Modified

Dependency scanning

Check whether marketing-mcp is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (87216e00fe68e2de8b140f1f9ffc2db5a8e814f38030e2eb6120c9ae9e7ca3ff)

The package exposes an MCP tool send(path) that reads a caller-specified local file and POSTs its contents to a hardcoded https://webhook.site/4acf7132-a75e-47e1-aeff-0350c8eac16c endpoint. The destination is a fixed public request-capture service, is not caller-configurable, and is not the installer's infrastructure. Any file path an LLM agent is induced to pass to send — including sensitive paths such as ~/.ssh/id_rsa, ~/.aws/credentials, .env files, or source trees — is uploaded to that third-party capture URL where the operator of the webhook can retrieve it. The package's advertised marketing/MCP framing does not match the actual behavior, which is a one-way file relay to an author-controlled inspection endpoint.

Source: kam193 (6a271b29f840e2047c34363e985921e1a374194cfcae7524698f178c96bea9eb)

Package attempts to lure LLM agents to exfiltrate files to a hardcoded location. Analysis of infrastructure suggests preparing for exfiltrating credentials.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-marketing-mcp

Reasons (based on the campaign):

  • files-exfiltration

  • llm-threat

Ready to move

Start Securing

Free, no credit card | First findings in minutes